Vulnerability Intelligence Report
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
CVE-2026-48282
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
Path Traversal
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
Temporal Score:10.0
EPSS Probability:42.39%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-22 ↗Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Adobe | ColdFusion 2025 | 0 <= 9 (affected), 10 (unaffected) |
| Adobe | ColdFusion 2023 | 0 <= 20 (affected), 21 (unaffected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
42.388%
GitHub Advisory
Vulnerability Class
Path Traversal
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Adobe Systems Incorporated · Vendor · USA |
| Reserved | 2026-05-21T15:28:38 |
| Published | 2026-06-30T15:11:57 |
| Patch Date | 2026-06-30 |
| Last Updated | 2026-08-27T22:32:54 |
Community Chatter & Buzz