10

CVE-2026-48282

Warnung
Medienbericht

ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Coldfusion Version 2023 Update -
Adobe ≫ Coldfusion Version 2023 Update update1
Adobe ≫ Coldfusion Version 2023 Update update10
Adobe ≫ Coldfusion Version 2023 Update update11
Adobe ≫ Coldfusion Version 2023 Update update12
Adobe ≫ Coldfusion Version 2023 Update update13
Adobe ≫ Coldfusion Version 2023 Update update14
Adobe ≫ Coldfusion Version 2023 Update update15
Adobe ≫ Coldfusion Version 2023 Update update16
Adobe ≫ Coldfusion Version 2023 Update update17
Adobe ≫ Coldfusion Version 2023 Update update18
Adobe ≫ Coldfusion Version 2023 Update update19
Adobe ≫ Coldfusion Version 2023 Update update2
Adobe ≫ Coldfusion Version 2023 Update update20
Adobe ≫ Coldfusion Version 2023 Update update3
Adobe ≫ Coldfusion Version 2023 Update update4
Adobe ≫ Coldfusion Version 2023 Update update5
Adobe ≫ Coldfusion Version 2023 Update update6
Adobe ≫ Coldfusion Version 2023 Update update7
Adobe ≫ Coldfusion Version 2023 Update update8
Adobe ≫ Coldfusion Version 2023 Update update9
Adobe ≫ Coldfusion Version 2025 Update -
Adobe ≫ Coldfusion Version 2025 Update update1
Adobe ≫ Coldfusion Version 2025 Update update2
Adobe ≫ Coldfusion Version 2025 Update update3
Adobe ≫ Coldfusion Version 2025 Update update4
Adobe ≫ Coldfusion Version 2025 Update update5
Adobe ≫ Coldfusion Version 2025 Update update6
Adobe ≫ Coldfusion Version 2025 Update update7
Adobe ≫ Coldfusion Version 2025 Update update8
Adobe ≫ Coldfusion Version 2025 Update update9
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login

07.07.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

Adobe ColdFusion Path Traversal Vulnerability

Schwachstelle

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

Beschreibung

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 99.24% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Adobe 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
14.07.2026 20:08
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.07.2026 09:19
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.07.2026 08:34
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
06.07.2026 15:32
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
06.07.2026 15:32
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
02.07.2026 09:59
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
01.07.2026 17:44
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
01.07.2026 09:58
https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48282
US Government Resource