Junglewise Threat Intelligence

CVE-2026-48314: Adobe ColdFusion path traversal in file management

CVE-2026-48314 · Severity: medium · CVSS 6.5 · Published 2026-06-30

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security flaw that allows unauthorized access to the server's file system. An attacker could exploit this to read or write files they should not have access to, potentially compromising sensitive data or altering application behavior. This vulnerability can be exploited remotely without any user interaction.

Technical details

A path traversal vulnerability (CWE-22) exists in Adobe ColdFusion versions 2025.9, 2023.20, and earlier. The flaw stems from improper limitation of pathnames to restricted directories, allowing an attacker to bypass security features. A remote, unauthenticated attacker can exploit this vulnerability without user interaction to gain limited read and write access to files or directories outside of the intended web root or restricted areas. The vulnerability is assigned a CVSS score of 6.5, reflecting partial impact on confidentiality and integrity. Users are advised to review Adobe advisory APSB26-68 for patching information.

Affected products

  • Adobe ColdFusion 2025.9, 2023.20 and earlier

Timeline

  • 2026-06-30: disclosed: Initial disclosure by Adobe and NVD publication
  • 2026-06-30: advisory: Adobe released security bulletin APSB26-68

References

Related threats