Path Traversal in ColdFusion by Adobe
CVE-2026-48313

9.3CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
30 June 2026

What is CVE-2026-48313?

ColdFusion versions 2025.9 and 2023.20 are susceptible to a Path Traversal vulnerability. This flaw allows attackers to gain unauthorized access to sensitive files and directories that are outside the designated access control boundaries. The vulnerability can be exploited without any user interaction, posing a significant risk to security and data integrity.

Affected Version(s)

ColdFusion 0 <= 2023.20

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.