ZeroHour

CVE-2026-27305

large

Unauthenticated Path Traversal Arbitrary File Read in Adobe ColdFusion 2023/2025

CVSS 3.1
8.6 high
EPSS
29%p98
Published
()
Modified
AI analysis

CVE-2026-27305 is an improper limitation of a pathname to a restricted directory (path traversal, CWE-22) in Adobe ColdFusion that allows an unauthenticated remote attacker to read arbitrary files on the server. The flaw is reachable over the network and requires no user interaction or privileges, and with CVSS scope changed (S:C), file reads can escape the application's intended directory scope. An attacker who exploits it gains read access to sensitive files outside the intended access boundary, such as application configuration files and any credentials they contain, with no direct integrity or availability impact (CVSS 3.1: 8.6, C:H/I:N/A:N). Any organization running ColdFusion 2023 update 18 (2023.18) or earlier, or ColdFusion 2025 update 6 (2025.6) or earlier, whether internet-facing or internal, is affected. The issue is not on CISA's KEV list and no public proof-of-concept is known, but EPSS assigns a 29% probability of exploitation within 30 days (98th percentile), so exploitation is considered likely soon.

What to do: Upgrade all ColdFusion 2023 instances to a build later than 2023.18 and all ColdFusion 2025 instances to a build later than 2025.6 using Adobe's April Patch Tuesday security bulletin, and verify the installed update level in the ColdFusion Administrator. Until patched, restrict network access to ColdFusion servers, prioritizing internet-facing instances, and monitor for anomalous file-read activity. Treat this as high priority given the 29% EPSS likelihood of exploitation within 30 days even though no public PoC exists yet.

Affected
Adobe ColdFusion 2023update 18 (2023.18) and earlier
Adobe ColdFusion 2025update 6 (2025.6) and earlier
Estimated exposure
largetens of thousands of internet-exposed ColdFusion servers (order of magnitude 10k–100k); many more internal deployments — estimate — Based on public internet-wide scan data (e.g., Shodan), on the order of tens of thousands of ColdFusion servers are directly exposed on the internet, with a larger unknown installed base running internally in enterprises.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.

Vendors
adobe
Products
coldfusion
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

In the news