Junglewise Threat Intelligence

CVE-2026-48313: Adobe ColdFusion path traversal leading to arbitrary file read

CVE-2026-48313 · Severity: critical · CVSS 9.3 · Published 2026-06-30

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform used for building and deploying web applications, contains a critical security flaw. This vulnerability allows an unauthorized person to bypass security restrictions to read sensitive files and potentially modify certain data on the server. This could lead to the exposure of confidential business information or system credentials without requiring any interaction from a legitimate user.

Technical details

A path traversal vulnerability (CWE-22) exists in Adobe ColdFusion due to improper limitation of a pathname to a restricted directory. The flaw allows a remote, unauthenticated attacker to send specially crafted requests to the server to access files and directories outside of the web root. This can result in arbitrary file system read access and limited write capabilities. The vulnerability is particularly severe as it involves a 'Scope Change' (Status: C in CVSS), indicating the impact extends beyond the ColdFusion application environment to the underlying operating system or other hosted applications. No user interaction is required for successful exploitation.

Affected products

  • Adobe ColdFusion 2025.9, 2023.20 and earlier

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory: Adobe security bulletin APSB26-68 released.

References

Related threats