CVE-2026-48313: ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited write access. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48313?
CVE-2026-48313 has a critical severity rating of 9.3.
How do I fix CVE-2026-48313?
To fix CVE-2026-48313, update your Adobe ColdFusion to a version later than 2025.9 or 2023.20.
What systems are vulnerable to CVE-2026-48313?
CVE-2026-48313 affects Adobe ColdFusion versions 2025.9, 2023.20, and earlier.
What type of attack does CVE-2026-48313 enable?
CVE-2026-48313 enables attackers to perform path traversal attacks leading to arbitrary file system read and limited write access.
What are the potential impacts of CVE-2026-48313?
The potential impacts of CVE-2026-48313 include unauthorized access to sensitive files and information on the server.