Path Traversal Vulnerability in Adobe ColdFusion Products
CVE-2026-48282

10CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
30 June 2026

What is CVE-2026-48282?

Adobe ColdFusion versions 2025.9 and 2023.20, along with earlier releases, are susceptible to a Path Traversal vulnerability. This flaw allows attackers to bypass security restrictions and potentially execute arbitrary code within the context of the affected user account. Importantly, exploitation does not necessitate user interaction, making this issue particularly critical for organizations utilizing these versions of ColdFusion. For detailed information and remediation steps, refer to Adobe's official security advisory.

Affected Version(s)

ColdFusion 0 <= 2023.20

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.