CVE-2026-34619: ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34619?
The severity of CVE-2026-34619 is significant due to its potential for unauthorized file access through path traversal.
How do I fix CVE-2026-34619?
To fix CVE-2026-34619, upgrade Adobe ColdFusion to version 2023.19 or later and 2025.7 or later.
What versions of ColdFusion are affected by CVE-2026-34619?
CVE-2026-34619 affects Adobe ColdFusion versions 2023.18, 2025.6, and earlier.
What type of vulnerability is CVE-2026-34619?
CVE-2026-34619 is classified as a Path Traversal vulnerability, which allows attackers to access restricted directories.
Can CVE-2026-34619 lead to data leakage?
Yes, CVE-2026-34619 can potentially lead to data leakage by allowing unauthorized access to sensitive files.