CVE Record
[ CRITICAL ]CVE-2026-48319
Adobe ColdFusion path traversal — CVSS 9.1
Path traversal in Adobe ColdFusion allows an unauthenticated remote attacker to read arbitrary files on the server. Patched in ColdFusion 2025 Update 11 and 2023 Update 22.
- Vendor
- Adobe
- Product
- ColdFusion 2023, ColdFusion 2025
- CVSS
- 9.1
- EPSS (exploit probability)
- 32.3%
- Status
- patched
- Published
A path traversal vulnerability in Adobe ColdFusion allows an unauthenticated remote attacker to access files outside of the intended directory, potentially exposing sensitive server-side configuration and credentials. Part of Adobe’s July 2026 ColdFusion update batch fixing eight critical vulnerabilities.
Apply ColdFusion 2025 Update 11 or ColdFusion 2023 Update 22. See also CVE-2026-48318, a higher-severity path traversal (CVSS 9.9) in the same update batch.
Source: NVD · Adobe Security Bulletin
