CVE-2026-48364
Analyzed Analyzed - Analysis Complete

Uncontrolled Search Path Element in Adobe ColdFusion

Vulnerability report for CVE-2026-48364, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-13

Last updated on: 2026-07-15

Assigner: Adobe Systems Incorporated

Description

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-13
Last Modified
2026-07-15
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD

Affected Vendors & Products

Showing 31 associated CPEs
Vendor Product Version / Range
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2025
adobe coldfusion 2023
adobe coldfusion 2025
adobe coldfusion 2023
adobe coldfusion 2025
adobe coldfusion 2023
adobe coldfusion 2025
adobe coldfusion 2023
adobe coldfusion 2025
adobe coldfusion 2025
adobe coldfusion 2023
adobe coldfusion 2025
adobe coldfusion 2023
adobe coldfusion 2023
adobe coldfusion 2025
adobe coldfusion 2025
adobe coldfusion 2023
adobe coldfusion 2025

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-427 The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-48364 is an Uncontrolled Search Path Element vulnerability affecting ColdFusion versions 2025.9, 2023.20, and earlier. This type of vulnerability occurs when an application uses an uncontrolled search path to load libraries or other resources, allowing an attacker to manipulate the path and load malicious files instead.

In this case, exploitation requires user interaction, meaning a victim must open a malicious file. If exploited, the vulnerability could result in arbitrary code execution in the context of the current user. The scope of the vulnerability is changed, indicating it may affect components beyond the initial security boundary.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the Uncontrolled Search Path Element vulnerability in ColdFusion versions 2025.9, 2023.20, and earlier.

Generally, to detect such vulnerabilities, you might check for unusual or unauthorized file paths in ColdFusion configurations, monitor for unexpected file execution, or use vulnerability scanning tools that support Adobe ColdFusion. However, no explicit commands or tools are mentioned in the given context.

Impact Analysis

If you are using an affected version of ColdFusion (2025.9, 2023.20, or earlier), this vulnerability could have several impacts:

  • Arbitrary code execution: An attacker could execute malicious code on your system with the privileges of the current user, potentially leading to full system compromise.
  • Data theft or manipulation: The attacker could access, modify, or delete sensitive data processed by ColdFusion.
  • System disruption: The vulnerability could be used to disrupt services or applications relying on ColdFusion.

Exploitation requires user interaction, such as opening a malicious file, so the risk may be mitigated by user awareness and cautious behavior.

Compliance Impact

This vulnerability could impact compliance with several common standards and regulations, depending on the context of its use:

  • GDPR (General Data Protection Regulation): If ColdFusion processes personal data of EU citizens, this vulnerability could lead to unauthorized access or disclosure of that data, violating GDPR requirements for data protection and security. Organizations may face fines or legal action if they fail to mitigate the risk.
  • HIPAA (Health Insurance Portability and Accountability Act): If ColdFusion is used in a healthcare environment to handle protected health information (PHI), exploitation of this vulnerability could result in unauthorized access to PHI, violating HIPAA's security and privacy rules. This could lead to penalties and reputational damage.
  • Other standards: Compliance with frameworks like ISO 27001, NIST, or PCI DSS may also be affected, as these require organizations to maintain secure systems and protect against unauthorized access or code execution vulnerabilities.

Organizations should assess their exposure to this vulnerability and take appropriate remediation steps to maintain compliance with applicable regulations.

Mitigation Strategies

Based on the provided context, here are some immediate steps to mitigate the vulnerability:

  • Apply the latest security patches or updates provided by Adobe for ColdFusion versions 2025.9, 2023.20, and earlier. The context does not specify a patch, but Adobe typically releases fixes for such vulnerabilities.
  • Restrict user interactions with untrusted or malicious files, as exploitation requires a victim to open a malicious file.
  • Review and harden the ColdFusion installation by ensuring that only trusted directories are included in the search path for libraries or configuration files.
  • Monitor for unusual activity or unauthorized code execution within the ColdFusion environment.
  • Consider implementing application control or whitelisting solutions to prevent the execution of unauthorized files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-48364. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart