---
id: CVE-2026-48282
title: >-
  ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper
  Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  vulnerability that could lead to arbitrary code execution in the context of
  the current use…
summary: >-
  ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper
  Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  vulnerability that could lead to arbitrary code execution in the context of
  the current use…
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: adobe
product: coldfusion
affected:
  - coldfusion = 2023
  - coldfusion = 2025
published: '2026-06-30'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:37.797'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-48282'
references:
  - url: 'https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html'
    label: psirt@adobe.com
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48282
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
  - cve.org
epss: 0.42388
epssPercentile: 0.98668
kev: true
kevDateAdded: '2026-07-07'
kevDueDate: '2026-07-10'
kevRansomware: false
exploited: true
exploits:
  github: 3
  githubRepos:
    - 'https://github.com/imbas007/CVE-2026-48282'
    - 'https://github.com/g0thamRabb1t/CVE-2026-48282-coldfusion-rds-detection'
    - 'https://github.com/arpit-bansal15/cve-2026-48282-pentest-lab'
  nuclei:
    - CVE-2026-48282
  checkedAt: '2026-10-07T20:47:22.833Z'
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-07-08T03:56:31.827098Z'
ingestedAt: '2026-10-07T18:42:20.903Z'
---

## Overview

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

## Affected

- `coldfusion = 2023`
- `coldfusion = 2025`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
