CVE-2026-75998
largeUnauthenticated Arbitrary File Read in Adobe ColdFusion
Adobe ColdFusion contains an Improper Access Control flaw (CWE-284) that allows an attacker to read arbitrary files and directories on the file system outside the intended access scope. The vulnerability is reachable over the network and requires no user interaction and no privileges, per the CVSS vector (AV:N/AC:L/PR:N/UI:N). A successful exploit yields high confidentiality impact only — the attacker can retrieve sensitive files such as configuration files and credentials — with no integrity or availability impact. All Adobe ColdFusion deployments are potentially affected, though the data provided does not specify affected or patched version ranges. As of now there is no known exploitation: it is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.6% probability of exploitation within 30 days.
What to do: Monitor Adobe's security advisory (CNA: [email protected]) for the affected product versions and upgrade to the patched release as soon as it is published. Until then, limit network exposure of ColdFusion servers (restrict access at the firewall/WAF level) and audit what sensitive files — such as application configuration files containing database or service credentials — could be exposed via an unauthenticated file read.
| Adobe ColdFusion | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ColdFusion is affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.