Path Traversal Vulnerability in ColdFusion by Adobe
CVE-2026-34619

7.7HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
14 April 2026

What is CVE-2026-34619?

ColdFusion versions 2023.18, 2025.6, and earlier are susceptible to a path traversal vulnerability that allows attackers to bypass security measures and gain access to unauthorized files or directories. Exploiting this vulnerability does not require any user interaction, making it particularly concerning for system administrators.

Affected Version(s)

ColdFusion 0 <= 2025.6

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.