CVE-2026-34619
Adobe ColdFusion, coldfusion
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction.
- CVSS
- 7.7
- EPSS
- 8.51% 94.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.15