Path Traversal Vulnerability in Adobe ColdFusion Products
CVE-2026-48282
10CRITICAL
What is CVE-2026-48282?
Adobe ColdFusion versions 2025.9 and 2023.20, along with earlier releases, are susceptible to a Path Traversal vulnerability. This flaw allows attackers to bypass security restrictions and potentially execute arbitrary code within the context of the affected user account. Importantly, exploitation does not necessitate user interaction, making this issue particularly critical for organizations utilizing these versions of ColdFusion. For detailed information and remediation steps, refer to Adobe's official security advisory.
Affected Version(s)
ColdFusion 0 <= 2023.20