CVE-2026-47932: ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47932?
The severity of CVE-2026-47932 is rated high with a score of 8.8.
How do I fix CVE-2026-47932?
To fix CVE-2026-47932, upgrade to ColdFusion version 2023.20 or later, or 2025.9 or later.
What types of attacks can exploit CVE-2026-47932?
CVE-2026-47932 can be exploited to bypass security features and access unauthorized files or directories.
Which versions of Adobe ColdFusion are affected by CVE-2026-47932?
Adobe ColdFusion versions 2023.19, 2025.8 and earlier are affected by CVE-2026-47932.
What is a Path Traversal vulnerability like in CVE-2026-47932?
A Path Traversal vulnerability, as seen in CVE-2026-47932, allows attackers to manipulate file paths to access restricted files and directories.