CVE-2026-48313

Adobe Security Bulletin APSB26-68 — Coldfusion

criticalEPSS 2.9 %

Beschreibung

ColdFusion-Versionen 2025.9, 2023.20 und früher sind von einer Schwachstelle betroffen, die als "Unzureichende Einschränkung eines Pfadnamens auf ein eingeschränktes Verzeichnis" ('Pfad Traversal') bezeichnet wird. Diese Schwachstelle könnte zu einem beliebigen Dateisystem-Lesen und eingeschränktem Schreibzugriff führen. Ein Angreifer könnte diese Schwachstelle ausnutzen, um auf sensible Dateien und Verzeichnisse außerhalb des vorgesehenen Zugriffsbereichs zuzugreifen. Die Ausnutzung dieses Problems erfordert keine Benutzerinteraktion. Der Geltungsbereich wurde geändert.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.3
Quelle: nvd-v3
86.4 %
Kritisch — CVE liegt im obersten Fünftel aller heute bewerteten CVEs (Rang ≥ 80 %).
2.9 %
Moderat — Modell schätzt 1-10 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-06-30 16:16 UTC
CWE-22

Weakness-Klassen (CWE)

  • CWE-22Base

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-08-28 00:17 UTC· psirt@adobe.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/48xxx/CVE-2026-48313.json">CVE-2026-48313</a>
    • Reference: https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html
    • Reference: https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html
    • Reference Type: https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html Types: Vendor Advisory
  2. CVE Modified2026-08-24 22:16 UTC· psirt@adobe.com
    • Affected: ColdFusionColdFusion 2025, ColdFusion 2023
  3. Initial Analysis2026-06-30 20:44 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update7:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update6:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update8:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update9:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:-:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update13:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update1:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update14:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update2:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update15:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update3:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update16:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update4:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update5:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update18:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update6:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update17:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update19:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update7:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update8:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2023:update20:*:*:*:*:*:* *cpe:2.3:a:adobe:coldfusion:2025:update9:*:*:*:*:*:*
    • Reference Type: Adobe Systems Incorporated: https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html Types: Vendor Advisory

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • adobe

    coldfusion

Quellen & Referenzen

Verknüpfte CVEs

Verknüpfte Empfehlungen

IDCVE-2026-48313
Adobe Security Bulletin APSB26-68 — Coldfusion — CVE-2026-48313 | NEOSEC Intel