Executive brief
Adobe ColdFusion is an application server used to build and deploy web applications and services. An improper access control vulnerability allows attackers to read sensitive files and directories from the server's file system that should be restricted. This could expose configuration files, source code, database credentials, and other confidential data critical to business operations and customer privacy.
Technical details
ColdFusion is affected by an improper access control vulnerability (CWE-284) that permits arbitrary file system reads. The vulnerability allows attackers to access files and directories outside the intended scope of allowed access, likely through path traversal or inadequate authorization checks in file handling routines. The attack does not require user interaction and is network-accessible, making it exploitable by remote attackers. Successful exploitation results in confidentiality breach through unauthorized file disclosure. Adobe has released patches as indicated by the APSB26-119 security advisory.
Affected products
- Adobe ColdFusion
Timeline
- 2026-09-08: disclosed