CVE-2026-48282
About
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Rainforest analyst review
Adobe ColdFusion contains a path-traversal flaw in which a pathname is not properly restricted to an intended directory. By supplying traversal sequences, an attacker references locations outside the permitted scope, and in ColdFusion that reaches file operations powerful enough to result in arbitrary code execution in the context of the running user. Exploitation requires no user interaction and, given the network-reachable, no-privilege CVSS profile with changed scope, is triggered by a crafted request to the application server.
ColdFusion is an application server that historically sits internet-facing running business web applications, and it has a long track record of being aggressively targeted the moment a critical flaw surfaces, because a compromised server yields code execution on a host that often has access to back-end databases and internal systems. That pattern makes rapid patching essential rather than optional. Apply Adobe's update for the affected 2025 and 2023 release lines and any earlier supported versions immediately, apply the vendor's recommended lockdown and secure-configuration guidance, and keep ColdFusion administration off the public internet. Given ColdFusion's exploitation history, review exposed servers for web shells and unexpected files.
References
Related CVEs
Frequently asked questions
What is CVE-2026-48282?
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
How severe is CVE-2026-48282?
CVE-2026-48282 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.
How is CVE-2026-48282 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2026-48282?
Public advisories list the following as affected: coldfusion. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2026-48282?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
