Junglewise Threat Intelligence

CVE-2026-48282: Adobe ColdFusion path traversal in multiple versions

CVE-2026-48282 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2026-06-30

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform used for building and deploying web applications, contains a critical security flaw. An attacker can exploit this vulnerability to gain unauthorized access to the server's file system and execute malicious code. This could result in a complete takeover of the application, theft of sensitive customer data, or disruption of business operations. No user interaction is required for an attacker to trigger this issue.

Technical details

Adobe ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory (CWE-22), commonly known as path traversal. The vulnerability exists in versions 2025.9, 2023.20, and earlier. An unauthenticated remote attacker can exploit this flaw by sending specially crafted requests to the server to access files outside of the intended web root. This access can be leveraged to achieve arbitrary code execution (RCE) in the context of the service user. The vulnerability has a CVSS score of 10.0, as it requires no user interaction and results in a total impact on confidentiality, integrity, and availability. Adobe has released security updates to address this issue.

Affected products

  • Adobe ColdFusion 2025.9, 2023.20 and earlier

Timeline

  • 2026-06-30: advisory: Initial advisory published by Adobe and NVD entry created.
  • 2026-07-07: disclosed: Public disclosure date.

Related threats