Path Traversal in ColdFusion by Adobe
CVE-2026-48313
9.3CRITICAL
What is CVE-2026-48313?
ColdFusion versions 2025.9 and 2023.20 are susceptible to a Path Traversal vulnerability. This flaw allows attackers to gain unauthorized access to sensitive files and directories that are outside the designated access control boundaries. The vulnerability can be exploited without any user interaction, posing a significant risk to security and data integrity.
Affected Version(s)
ColdFusion 0 <= 2023.20