CVE-2026-47932
Adobe ColdFusion vulnerability analysis and mitigation

Overview

CVE-2026-47932 is a Path Traversal vulnerability (CWE-22) in Adobe ColdFusion that allows attackers to bypass security restrictions and access unauthorized files or directories outside intended boundaries. It affects ColdFusion 2023 versions up to and including 2023 Update 19, and ColdFusion 2025 versions up to and including 2025 Update 8. The vulnerability was disclosed and patched on June 9, 2026, as part of Adobe's APSB26-64 security advisory. It carries a CVSS v3.1 base score of 9.6 (Critical) per NVD, though the GitHub Advisory and ENISA rate it at 8.8 (High) using an adjacent network attack vector (Adobe Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and arises from insufficient validation of file path inputs within Adobe ColdFusion, allowing specially crafted pathnames to escape the intended restricted directory. Exploitation requires no privileges but does require user interaction — specifically, a victim must open a malicious file that triggers the path traversal logic. The scope is marked as "Changed," indicating that successful exploitation can impact components beyond the vulnerable ColdFusion instance itself. Attack patterns associated with this vulnerability include CAPEC-126 (Path Traversal), CAPEC-64 (Using Slashes and URL Encoding to Bypass Validation), and CAPEC-78/79 (Using Escaped/Alternate Slash Encodings) (Adobe Advisory, GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to read unauthorized files and directories outside the ColdFusion application's intended directory restrictions, resulting in high confidentiality, integrity, and availability impacts. Because the scope is changed, the vulnerability can affect resources and components beyond the directly vulnerable ColdFusion instance, potentially enabling lateral movement or access to sensitive server-side configuration files, credentials, or application data. The attack requires a victim to open a malicious file, but once triggered, the attacker gains broad access to the underlying file system (Adobe Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or adjacent-network Adobe ColdFusion instances running versions 2023 Update 19 or earlier, or 2025 Update 8 or earlier, using network scanning tools or service fingerprinting.
  2. Craft malicious file: Prepare a malicious file (e.g., a specially crafted ColdFusion template or uploaded document) containing path traversal sequences such as ../, URL-encoded variants (%2e%2e%2f), or alternate slash encodings designed to escape the restricted directory.
  3. Deliver malicious file: Deliver the malicious file to a victim user of the ColdFusion application via phishing, a malicious link, or by uploading it to an accessible location within the application.
  4. Trigger user interaction: Induce the victim to open or process the malicious file within the ColdFusion environment, which triggers the path traversal vulnerability.
  5. Access unauthorized files: The traversal payload causes ColdFusion to resolve file paths outside the intended restricted directory, granting the attacker read access to sensitive files such as configuration files, credentials, or other server-side resources (Adobe Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: ColdFusion application logs showing file access requests containing path traversal sequences such as ../, %2e%2e/, %2f, or encoded slash variants; unexpected access to files outside the web root or application directory.
  • File System: Unexpected reads of sensitive files (e.g., web.xml, password.properties, system configuration files) by the ColdFusion process; presence of unusual or externally uploaded files in ColdFusion-accessible directories.
  • Network: Unusual inbound requests from adjacent network hosts delivering files to ColdFusion endpoints; outbound connections from the ColdFusion server to unknown external hosts following file processing events.
  • Process: ColdFusion server process accessing directories or files outside its configured web root or application sandbox, observable via file system auditing or endpoint detection tools.

Mitigation and workarounds

Adobe has released security updates addressing this vulnerability: users should upgrade ColdFusion 2023 to Update 20 or later, and ColdFusion 2025 to Update 9 or later, as detailed in the APSB26-64 advisory (Adobe Advisory). As a complementary measure, administrators should implement file upload restrictions and input validation controls to limit the types and paths of files users can submit to the application. User awareness training to prevent opening untrusted or unexpected files is also recommended, given that exploitation requires victim interaction.

Community reactions

Adobe's June 2026 patch day, which addressed over 120 vulnerabilities across multiple products including ColdFusion, received coverage from Heise and other security news outlets (Heise). The Hacker Wire published a dedicated article on CVE-2026-47932, highlighting the path traversal and security bypass nature of the flaw (The Hacker Wire). Check Point also published a defense advisory (CPAI-2026-6508) covering the vulnerability. Community discussion on Bluesky noted the disclosure, and security aggregators such as BeyondMachines and Fortress SRM included it in their June 2026 threat roundups.

Additional resources


SourceThis report was generated using AI

Related Adobe ColdFusion vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48327CRITICAL9
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesJul 14, 2026
CVE-2026-48332HIGH7.7
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesJul 14, 2026
CVE-2026-48328HIGH7.7
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesJul 14, 2026
CVE-2026-48338MEDIUM6.8
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesJul 14, 2026
CVE-2026-48329LOW2.7
  • Adobe ColdFusion logoAdobe ColdFusion
  • cpe:2.3:a:adobe:coldfusion
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management