PT-2026-53903 · Adobe · Coldfusion
CVE-2026-48282
·
Published
2026-06-30
·
Updated
2026-07-20
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Adobe ColdFusion versions prior to 2025 Update 10
Adobe ColdFusion versions prior to 2023 Update 21
Description
Adobe ColdFusion contains a path traversal issue caused by improper limitation of a pathname to a restricted directory. The RDS FILEIO handler at the endpoint '/CFIDE/main/ide.cfm' with the parameter
ACTION=FILEIO fails to canonicalize user-supplied paths, allowing traversal sequences or absolute paths to escape the root directory. This enables an unauthenticated remote attacker to read and write arbitrary files on the system, which can be leveraged to upload a CFML webshell and achieve arbitrary code execution in the context of the ColdFusion service account. This issue has been actively exploited in the wild, with approximately 800 servers reported as accessible on the internet.Recommendations
Update Adobe ColdFusion 2025 to Update 10.
Update Adobe ColdFusion 2023 to Update 21.
Rotate CF admin, database, and service account credentials if anomalous file writes are detected.
Exploit
Fix
RCE
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coldfusion