« Volver al listado

CVE-2026-48314

Estado: AnalizadaMedia (6.5)—

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain limited read and write access to unauthorized files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-48314",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-48314",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-30T15:54:57.453065Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@adobe.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@adobe.com",
      "affectedData": [
        {
          "vendor": "Adobe",
          "product": "ColdFusion 2025",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "9"
            },
            {
              "status": "unaffected",
              "version": "10",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Adobe",
          "product": "ColdFusion 2023",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "20"
            },
            {
              "status": "unaffected",
              "version": "21",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-06-30T16:16:55.200",
  "references": [
    {
      "url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@adobe.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain limited read and write access to unauthorized files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction."
    }
  ],
  "lastModified": "2026-08-28T00:17:47.207",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B02A37FE-5D31-4892-A3E6-156A8FE62D28"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0AA3D302-CFEE-4DFD-AB92-F53C87721BFF"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "645D1B5F-2DAB-4AB8-A465-AC37FF494F95"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED6D8996-0770-4C9F-BEA5-87EA479D40A5"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4836086E-3D4A-4A07-A372-382D385CB490"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update13:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBC19168-4184-4B59-B9C8-E98844124EED"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update14:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A60DCD92-9A5B-411C-9554-642C91D77FAE"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update15:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58CC65EF-60A3-4DFA-AA51-E5013F116CEA"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E3EBFB1-4488-4924-A2E2-B7E422D68345"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update17:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A683F9B2-A0DC-4AA0-BE97-9E74FA200AB1"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update18:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8689F35F-9A81-45D2-B782-DBA12306BA45"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update19:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5FAA5985-4B25-46C5-8064-0713AB251704"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB88D4FE-5496-4639-BAF2-9F29F24ABF29"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update20:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E3884AF-7A1A-4604-B653-6694B7BD1E86"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43E0ED98-2C1F-40B8-AF60-FEB1D85619C0"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76204873-C6E0-4202-8A03-0773270F1802"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1A22BE9-0D47-4BA8-8BDB-9B12D7A0F7C7"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3A83642-BF14-4C37-BD94-FA76AABE8ADC"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A892E1DC-F2C8-4F53-8580-A2D1BEED5A25"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB97ADBA-C1A9-4EE0-9509-68CB12358AE5"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2023:update9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E17C38F0-9B0F-4433-9CBD-6E3D63EA9BDC"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2025:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30779417-D4E5-4A01-BE0E-1CE1D134292A"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2025:update1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80D7FC6A-F264-4CB1-A18D-B091EBA47882"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2025:update2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3DA0D20-93BA-4C76-A400-159853CD7277"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2025:update3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BAB6F21-61F1-43AB-88BA-553CD9AD6C0E"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2025:update4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C85288B9-5D63-49EA-828A-8DB3BB2367F6"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2025:update5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3882A011-5A01-48E7-B5E7-5A837B1CE245"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2025:update6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AACCE621-3380-4144-BA1B-AA26FE96B902"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2025:update7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EBC62370-3FA2-4AF7-A201-4155D09051F3"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2025:update8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7616F34-9422-4815-806F-4484F68ED2A8"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2025:update9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB078BC9-164F-46D0-99F8-086F93FF2046"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@adobe.com"
}