← Back to browse · API

CVE-2026-27305

Severity
HIGH
CVSS
8.6
EPSS
0.28962
Risk score
44.54
CISA KEV
No
PoC
No
Published
2026-04-14
Modified
2026-04-16
First seen
2026-08-05
Aliases
CNVD-2026-21644, EUVD-2026-22732
Products
Adobe ColdFusion 2023 <=Update 18, Adobe ColdFusion 2025 <=Update 6, Adobe:ColdFusion 0 ≤2025.6, adobe:coldfusion
Sources
nvd CVE-2026-27305
cnvd CNVD-2026-21644
euvd EUVD-2026-22732

Description

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.

References