Junglewise Threat Intelligence

CVE-2026-48338: Adobe ColdFusion path traversal arbitrary file read

CVE-2026-48338 · Severity: medium · CVSS 6.8 · Published 2026-07-14

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security flaw that allows unauthorized access to the server's file system. An attacker with access to the local network could exploit this to read sensitive configuration files, source code, or system data. This could lead to the exposure of credentials or other private information, potentially facilitating further attacks on the organization's infrastructure.

Technical details

Adobe ColdFusion (versions 2023 and 2025) contains a path traversal vulnerability (CWE-22) due to improper limitation of a pathname to a restricted directory. The vulnerability allows an authenticated attacker on an adjacent network to bypass directory restrictions and perform arbitrary file system reads. The exploit does not require user interaction and results in a changed scope (S:C), meaning the impact extends beyond the ColdFusion application environment to the underlying host operating system. Patches are available in ColdFusion 2025 Update 11 and ColdFusion 2023 Update 22.

Affected products

  • Adobe ColdFusion 2025 <= 10
  • Adobe ColdFusion 2023 <= 21

Timeline

  • 2026-07-14: advisory: Adobe published security bulletin APSB26-82
  • 2026-07-14: disclosed

References

Related threats