CVE-2026-48319
largePath Traversal Leading to Arbitrary Code Execution in Adobe ColdFusion
CVE-2026-48319 is a path traversal vulnerability (CWE-22, Improper Limitation of a Pathname to a Restricted Directory) in Adobe ColdFusion in which insufficiently restricted pathnames allow an attacker to escape an intended directory. The flaw is reachable over the network and requires no user interaction, but the attacker must already hold high privileges (PR:H), such as an administrative-level context, to trigger it. The 'scope changed' element of the CVSS score indicates a successful exploit crosses the vulnerable component's security boundary, and the attacker gains arbitrary code execution in the context of the current user, with high impact on confidentiality, integrity, and availability. Any organization running Adobe ColdFusion is potentially affected, especially deployments where privileged interfaces are network-reachable. The flaw is not yet in CISA's KEV and no public proof-of-concept is known, but its EPSS of 32.3% (98th percentile) signals a materially elevated likelihood of exploitation within 30 days.
What to do: Apply Adobe's ColdFusion security update for CVE-2026-48319 as soon as possible, using the version guidance in Adobe's bulletin since no fixed versions are specified in this data. Until patched, restrict network access to privileged ColdFusion interfaces and audit which accounts hold the high privileges required to exploit this flaw. With no public PoC or KEV listing yet, prioritize patching based on the elevated EPSS score and monitor Adobe advisories and threat feeds for signs of in-the-wild exploitation.
| Adobe ColdFusion | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
- Vendors
- adobe
- Products
- coldfusion
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H