Junglewise Threat Intelligence

CVE-2026-75998: Adobe ColdFusion improper access control arbitrary file read

CVE-2026-75998 · Severity: high · CVSS 7.5 · Published 2026-09-08

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion is an application server used to build and deploy web applications and services. An improper access control vulnerability allows attackers to read sensitive files and directories from the server's file system that should be restricted. This could expose configuration files, source code, database credentials, and other confidential data critical to business operations and customer privacy.

Technical details

ColdFusion is affected by an improper access control vulnerability (CWE-284) that permits arbitrary file system reads. The vulnerability allows attackers to access files and directories outside the intended scope of allowed access, likely through path traversal or inadequate authorization checks in file handling routines. The attack does not require user interaction and is network-accessible, making it exploitable by remote attackers. Successful exploitation results in confidentiality breach through unauthorized file disclosure. Adobe has released patches as indicated by the APSB26-119 security advisory.

Affected products

  • Adobe ColdFusion

Timeline

  • 2026-09-08: disclosed

References

Related threats