PT-2026-32921 · Adobe · Coldfusion

Published

2026-04-14

·

Updated

2026-04-15

·

CVE-2026-27305

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe ColdFusion versions prior to 2025.6
Description An improper limitation of a pathname to a restricted directory allows unauthenticated attackers to perform a path traversal, which is a method used to access files and directories stored outside the intended folder. This can lead to arbitrary file system read, potentially exposing sensitive data. Exploitation of this issue does not require user interaction and involves the fetchCFSettingFile function.
Recommendations Update to a version later than 2025.6.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2026-05603
CVE-2026-27305
ZDI-26-264

Affected Products

Coldfusion