Executive brief
Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security flaw that could allow an attacker to run unauthorized commands on a system. To exploit this, an attacker would need to trick a legitimate user into opening a specially crafted malicious file. If successful, the attacker could gain full control over the affected system, potentially leading to data theft or service disruption.
Technical details
Adobe ColdFusion is vulnerable to an Uncontrolled Search Path Element (CWE-427) issue in versions 2025.9, 2023.20, and earlier. The vulnerability occurs when the application attempts to load a resource or library using an insecure search path, allowing an attacker to place a malicious file in a location that the application prioritizes. Exploitation requires a local attacker to have low-level privileges and necessitates user interaction, specifically requiring a victim to open a malicious file. Successful exploitation results in arbitrary code execution in the context of the current user, with a changed scope (S:C) indicating potential impact beyond the ColdFusion environment itself. Adobe has addressed this in security bulletin APSB26-68.
Affected products
- Adobe ColdFusion 2025.9, 2023.20 and earlier
Timeline
- 2026-07-13: disclosed
- 2026-07-13: advisory