Adobe ColdFusion Path Traversal Vulnerability Leading to Security Feature Bypass

Vulnerability

A path traversal vulnerability has been identified in Adobe ColdFusion versions 2023.18, 2025.6 and earlier. This vulnerability allows attackers to access unauthorized files or directories outside of the intended restrictions, potentially bypassing security features. Exploitation of this issue does not require user interaction.

Impact

Exploitation of this vulnerability could lead to unauthorized access to files or directories, allowing for a bypass of security features.

Remediation

Users are advised to update to ColdFusion 2025 Update 7 or ColdFusion 2023 Update 19. For more information, refer to the Adobe ColdFusion downloads page or the respective ColdFusion 2025 and 2023 Lockdown Guides.

Added: Apr 15, 2026, 12:25 AM
Updated: Apr 15, 2026, 12:25 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
1.3
exploitability
5.4
remediation
7.7
relevance
5.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.