Junglewise Threat Intelligence

CVE-2026-48318: Adobe ColdFusion path traversal arbitrary file read

CVE-2026-48318 · Severity: critical · CVSS 9.9 · Published 2026-07-14

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for building and deploying web applications, is affected by a critical security flaw that allows unauthorized access to the server's file system. An attacker could exploit this to read sensitive configuration files, credentials, or proprietary data stored on the server. This could lead to a full compromise of the application and the underlying server infrastructure.

Technical details

A path traversal vulnerability (CWE-22) exists in Adobe ColdFusion 2023 and 2025 due to improper limitation of pathnames to restricted directories. The flaw allows a network-based attacker with low privileges to bypass directory restrictions and read arbitrary files on the host operating system. The vulnerability is particularly severe as it involves a 'Scope Changed' (S:C) impact, indicating the exploit can affect components beyond the ColdFusion application itself. Adobe has released patches (ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22) to address this issue.

Affected products

  • Adobe ColdFusion 2025 <= 10
  • Adobe ColdFusion 2023 <= 21

Timeline

  • 2026-07-14: advisory: Adobe published APSB26-82 advisory
  • 2026-07-14: disclosed: CVE-2026-48318 published to NVD

References

Related threats