CVE-2026-27305: ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27305?
CVE-2026-27305 has been rated as a medium severity vulnerability due to its potential to allow arbitrary file access.
How do I fix CVE-2026-27305?
To fix CVE-2026-27305, update your Adobe ColdFusion version to 2025.7 or later, or to 2023.19 or later.
What are the affected versions in CVE-2026-27305?
Adobe ColdFusion versions 2023.18, 2025.6 and earlier are affected by CVE-2026-27305.
What type of vulnerability is CVE-2026-27305?
CVE-2026-27305 is classified as a Path Traversal vulnerability, which allows an attacker to access restricted directories.
What can happen if CVE-2026-27305 is exploited?
Exploitation of CVE-2026-27305 could lead to exposure of sensitive files on the server, potentially resulting in data leaks.