CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-48282

Critical · CVSS 10.0

Adobe ColdFusion — Path Traversal leading to arbitrary code execution (CWE-22)

CVSS
10.0
nvd
EPSS
KEV
No
Class
other
CWE-22

Description

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Search profile — drives PoC discovery

Symbols CVE-2026-48282APSB26-68ColdFusion 2025ColdFusion 2023path traversalarbitrary code execution
Keywords CVE-2026-48282APSB26-68ColdFusion path traversal RCEColdFusion 2025.9 exploitColdFusion 2023.20 exploitColdFusion arbitrary code executionColdFusion directory traversal PoC
Versions: ColdFusion 2025 <= 2025.9, ColdFusion 2023 <= 2023.20

Ranked PoCs (2) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-01T00:00:14.000Z · profiled 2026-07-01T18:30:14.000Z