PT-2026-32921 · Adobe · Coldfusion
Published
2026-04-14
·
Updated
2026-04-15
·
CVE-2026-27305
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe ColdFusion versions prior to 2025.6
Description
An improper limitation of a pathname to a restricted directory allows unauthenticated attackers to perform a path traversal, which is a method used to access files and directories stored outside the intended folder. This can lead to arbitrary file system read, potentially exposing sensitive data. Exploitation of this issue does not require user interaction and involves the
fetchCFSettingFile function.Recommendations
Update to a version later than 2025.6.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coldfusion