Junglewise Threat Intelligence

CVE-2026-48319: Adobe ColdFusion path traversal in directory handling

CVE-2026-48319 · Severity: critical · CVSS 9.1 · Published 2026-07-14

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform used for building and deploying web applications, is affected by a critical security vulnerability. An attacker could exploit this flaw to bypass directory restrictions and execute unauthorized commands on the server. This could lead to a complete takeover of the application, theft of sensitive data, or disruption of business operations.

Technical details

Adobe ColdFusion is vulnerable to a path traversal (CWE-22) flaw due to improper limitation of pathnames to restricted directories. The vulnerability allows a remote attacker with high privileges to bypass security restrictions via network requests. Successful exploitation enables arbitrary code execution in the context of the service user. The issue is characterized by a scope change (S:C) in the CVSS metric, indicating the impact extends beyond the ColdFusion application itself to the underlying host environment. Patches are available in ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22.

Affected products

  • Adobe ColdFusion 2025 <= 10
  • Adobe ColdFusion 2023 <= 21

Timeline

  • 2026-07-14: advisory: Adobe published security bulletin APSB26-82
  • 2026-07-14: disclosed

References

Related threats