CVE-2026-48338: ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48338?
The severity of CVE-2026-48338 is medium with a score of 6.8.
How do I fix CVE-2026-48338?
To fix CVE-2026-48338, ensure your Adobe ColdFusion is updated to the latest version that addresses this path traversal vulnerability.
What type of vulnerability is CVE-2026-48338?
CVE-2026-48338 is classified as a Path Traversal vulnerability, allowing access to unauthorized file system locations.
What is the potential impact of CVE-2026-48338?
The potential impact of CVE-2026-48338 includes arbitrary file system read, which could expose sensitive files outside the intended access scope.
Which software is affected by CVE-2026-48338?
CVE-2026-48338 affects Adobe ColdFusion installations that do not mitigate the path traversal vulnerability.