CVE-2026-48314: ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain limited read and write access to unauthorized files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48314?
The severity of CVE-2026-48314 is rated as medium with a score of 6.5.
How do I fix CVE-2026-48314?
To fix CVE-2026-48314, upgrade to the latest version of Adobe ColdFusion that addresses this vulnerability.
What type of vulnerability is CVE-2026-48314?
CVE-2026-48314 is classified as a Path Traversal vulnerability that allows limited access to unauthorized files.
Which versions of ColdFusion are affected by CVE-2026-48314?
CVE-2026-48314 affects ColdFusion versions 2025.9, 2023.20, and earlier.
What could an attacker achieve by exploiting CVE-2026-48314?
An attacker could gain limited read and write access to unauthorized directories due to the vulnerability in CVE-2026-48314.