CVE-2026-48282: Adobe ColdFusion Path Traversal Vulnerability
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
Other sources
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48282?
CVE-2026-48282 has a critical severity level of 10.
How do I fix CVE-2026-48282?
To fix CVE-2026-48282, update Adobe ColdFusion to version 2025.10 or 2023.21 or later.
What is the risk associated with CVE-2026-48282?
CVE-2026-48282 has a risk score of 87, indicating a high potential for exploitation.
Can CVE-2026-48282 be exploited without user interaction?
Yes, exploitation of CVE-2026-48282 does not require user interaction.
Which versions of ColdFusion are affected by CVE-2026-48282?
CVE-2026-48282 affects Adobe ColdFusion versions 2025.9, 2023.20, and earlier.