Executive brief
Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security flaw that allows unauthorized access to the server's file system. An attacker could exploit this to read or write files they should not have access to, potentially compromising sensitive data or altering application behavior. This vulnerability can be exploited remotely without any user interaction.
Technical details
A path traversal vulnerability (CWE-22) exists in Adobe ColdFusion versions 2025.9, 2023.20, and earlier. The flaw stems from improper limitation of pathnames to restricted directories, allowing an attacker to bypass security features. A remote, unauthenticated attacker can exploit this vulnerability without user interaction to gain limited read and write access to files or directories outside of the intended web root or restricted areas. The vulnerability is assigned a CVSS score of 6.5, reflecting partial impact on confidentiality and integrity. Users are advised to review Adobe advisory APSB26-68 for patching information.
Affected products
- Adobe ColdFusion 2025.9, 2023.20 and earlier
Timeline
- 2026-06-30: disclosed: Initial disclosure by Adobe and NVD publication
- 2026-06-30: advisory: Adobe released security bulletin APSB26-68