PT-2026-32934 · Adobe · Coldfusion

Published

2026-04-14

·

Updated

2026-04-15

·

CVE-2026-34619

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ColdFusion versions prior to 2025.7
Description An improper limitation of a pathname to a restricted directory, known as path traversal, allows unauthenticated attackers to bypass security restrictions. This issue enables access to unauthorized files or directories outside the intended paths by sending crafted requests. Exploitation does not require user interaction.
Recommendations Update to a version newer than 2025.6.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2026-05604
CVE-2026-34619
ZDI-26-262

Affected Products

Coldfusion