CVE-2026-48282
Critical · CVSS 10.0Adobe ColdFusion — Path Traversal leading to arbitrary code execution (CWE-22)
- CVSS
- 10.0
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-22
Description
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Search profile — drives PoC discovery
Symbols CVE-2026-48282APSB26-68ColdFusion 2025ColdFusion 2023path traversalarbitrary code execution
Keywords CVE-2026-48282APSB26-68ColdFusion path traversal RCEColdFusion 2025.9 exploitColdFusion 2023.20 exploitColdFusion arbitrary code executionColdFusion directory traversal PoC
Versions: ColdFusion 2025 <= 2025.9, ColdFusion 2023 <= 2023.20
Ranked PoCs (2) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 20
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-07-01T00:00:14.000Z · profiled 2026-07-01T18:30:14.000Z