CVE-2026-48282
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
- Published
- Jun 30, 2026
- Updated
- Aug 27, 2026
- Assigning CNA
- adobe
- Evidence observed
- Jul 7, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 98.7%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Sources
2Laboratory validation of CVE-2026-48282 in Adobe ColdFusion RDS with arbitrary CFM file write, code execution, auditd/PCAP evidence, event timeline reconstruction, and SOC detection recommendations. Includes English and Polish reports.
Proof-of-concept exploit for CVE-2026-48282, a critical path traversal in Adobe ColdFusion RDS enabling unauthenticated file read/write and RCE. Supports single-target and mass scanning with multi-threaded file extraction.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.