CVE-2026-48282
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code exe...
Affects 0 products across 1 vendor.
Attacker manipulates file path inputs to access files outside the intended directory.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical severity vulnerability (CVE-2026-48282) affects the target system. ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitati...
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-48282?
What is the CVSS score for CVE-2026-48282?
Is CVE-2026-48282 actively exploited?
How do I remediate CVE-2026-48282?
What systems are affected by CVE-2026-48282?
| CVE ID | CVE-2026-48282 |
|---|---|
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2026-06-30 |
| Last Modified | 2026-06-30 |
| Weakness (CWE) | |
| Source | NVD |
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Source: NIST NVD / MITRE CVE Database
| Vendor | Product | Fixed Version |
|---|---|---|
| Adobe | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | ● Active Exploitation Confirmed (added 2026-07-07) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
This Vulnerability Is Being Actively Exploited
CVE-2026-48282 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.
Start Free KEV Monitoring →