
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47932 is a Path Traversal vulnerability (CWE-22) in Adobe ColdFusion that allows attackers to bypass security restrictions and access unauthorized files or directories outside intended boundaries. It affects ColdFusion 2023 versions up to and including 2023 Update 19, and ColdFusion 2025 versions up to and including 2025 Update 8. The vulnerability was disclosed and patched on June 9, 2026, as part of Adobe's APSB26-64 security advisory. It carries a CVSS v3.1 base score of 9.6 (Critical) per NVD, though the GitHub Advisory and ENISA rate it at 8.8 (High) using an adjacent network attack vector (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and arises from insufficient validation of file path inputs within Adobe ColdFusion, allowing specially crafted pathnames to escape the intended restricted directory. Exploitation requires no privileges but does require user interaction — specifically, a victim must open a malicious file that triggers the path traversal logic. The scope is marked as "Changed," indicating that successful exploitation can impact components beyond the vulnerable ColdFusion instance itself. Attack patterns associated with this vulnerability include CAPEC-126 (Path Traversal), CAPEC-64 (Using Slashes and URL Encoding to Bypass Validation), and CAPEC-78/79 (Using Escaped/Alternate Slash Encodings) (Adobe Advisory, GitHub Advisory).
Successful exploitation allows an unauthenticated attacker to read unauthorized files and directories outside the ColdFusion application's intended directory restrictions, resulting in high confidentiality, integrity, and availability impacts. Because the scope is changed, the vulnerability can affect resources and components beyond the directly vulnerable ColdFusion instance, potentially enabling lateral movement or access to sensitive server-side configuration files, credentials, or application data. The attack requires a victim to open a malicious file, but once triggered, the attacker gains broad access to the underlying file system (Adobe Advisory, GitHub Advisory).
../, URL-encoded variants (%2e%2e%2f), or alternate slash encodings designed to escape the restricted directory.../, %2e%2e/, %2f, or encoded slash variants; unexpected access to files outside the web root or application directory.web.xml, password.properties, system configuration files) by the ColdFusion process; presence of unusual or externally uploaded files in ColdFusion-accessible directories.Adobe has released security updates addressing this vulnerability: users should upgrade ColdFusion 2023 to Update 20 or later, and ColdFusion 2025 to Update 9 or later, as detailed in the APSB26-64 advisory (Adobe Advisory). As a complementary measure, administrators should implement file upload restrictions and input validation controls to limit the types and paths of files users can submit to the application. User awareness training to prevent opening untrusted or unexpected files is also recommended, given that exploitation requires victim interaction.
Adobe's June 2026 patch day, which addressed over 120 vulnerabilities across multiple products including ColdFusion, received coverage from Heise and other security news outlets (Heise). The Hacker Wire published a dedicated article on CVE-2026-47932, highlighting the path traversal and security bypass nature of the flaw (The Hacker Wire). Check Point also published a defense advisory (CPAI-2026-6508) covering the vulnerability. Community discussion on Bluesky noted the disclosure, and security aggregators such as BeyondMachines and Fortress SRM included it in their June 2026 threat roundups.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."