Executive brief
Adobe ColdFusion, a platform used for building and deploying web applications, is affected by a critical security vulnerability. An attacker could exploit this flaw to bypass directory restrictions and execute unauthorized commands on the server. This could lead to a complete takeover of the application, theft of sensitive data, or disruption of business operations.
Technical details
Adobe ColdFusion is vulnerable to a path traversal (CWE-22) flaw due to improper limitation of pathnames to restricted directories. The vulnerability allows a remote attacker with high privileges to bypass security restrictions via network requests. Successful exploitation enables arbitrary code execution in the context of the service user. The issue is characterized by a scope change (S:C) in the CVSS metric, indicating the impact extends beyond the ColdFusion application itself to the underlying host environment. Patches are available in ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22.
Affected products
- Adobe ColdFusion 2025 <= 10
- Adobe ColdFusion 2023 <= 21
Timeline
- 2026-07-14: advisory: Adobe published security bulletin APSB26-82
- 2026-07-14: disclosed