← Vulnerability feed

Vulnerability record · CVE-2010-2861 · published 11 August 2010

CVE-2010-2861: Adobe ColdFusion administrator console path traversal file read

Adobe · Coldfusion

Adobe ColdFusion 9.0.1 and earlier contains directory traversal flaws in multiple administrator console pages, reachable through the locale parameter. An unauthenticated remote attacker can read arbitrary files from the server, which matters because ColdFusion configuration files often hold credentials and secrets.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 Known ransomware use EPSS 100% · top 0.1% CWE-22 · Path traversal
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
11References, 2 tagged exploit
14 Aug 2026Last modified by NVD

Description

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable arbitrary file read with CVSS 9.8, KEV listing with known ransomware use, and near-maximum EPSS probability.

What it is

Adobe ColdFusion 9.0.1 and earlier contains directory traversal flaws in multiple administrator console pages, reachable through the locale parameter. An unauthenticated remote attacker can read arbitrary files from the server, which matters because ColdFusion configuration files often hold credentials and secrets.

Impact

An attacker gains read access to arbitrary files on the host, including ColdFusion configuration and credential material, enabling further compromise. The CVSS 3.1 vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reached over the network via HTTP requests to CFIDE/administrator pages such as mappings.cfm, logging/settings.cfm, datasources/index.cfm, j2eepackaging/editarchive.cfm and enter.cfm, manipulating the locale parameter. The CVSS vector indicates no privileges and no user interaction are required.

Exploitation

Listed in CISA KEV since 2022-03-25 with known ransomware campaign use, and EPSS 30-day probability is 0.99721 (99.95th percentile). A public exploit reference is tagged in the record.

What to do

  • Apply the vendor update per Adobe security bulletin APSB10-18; upgrade ColdFusion to a supported fixed release.
  • If patching is not immediately possible, restrict network access to CFIDE/administrator paths to trusted management hosts only.
  • Remove or block the ColdFusion administrator console from internet-facing exposure.
  • Rotate credentials and secrets stored in ColdFusion configuration files that may have been exposed.
  • Monitor for and investigate any prior traversal attempts against the listed administrator pages.

Detection

  • Search web logs for requests to CFIDE/administrator pages (mappings.cfm, logging/settings.cfm, datasources/index.cfm, j2eepackaging/editarchive.cfm, enter.cfm) containing traversal sequences in the locale parameter.
  • Alert on encoded traversal patterns such as ../, ..%2f or %2e%2e%2f in requests to ColdFusion administrator endpoints.
  • Review file access and process telemetry for unexpected reads of ColdFusion configuration files by the web service account.
  • Correlate any hits with outbound connections or follow-on activity indicating credential use.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2010-2861 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Adobe ColdFusion Directory Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-2861 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-48282Adobe ColdFusion path traversal leads to remote code executionColdFusion versions 2025.9, 2023.20 and earlier contain a path traversal flaw (CWE-22) that allows an unauthenticated remote attacker to reach files …KEVEPSS 42%analysed9.8CVE-2023-38203Adobe ColdFusion untrusted data deserialization allows remote code executionAdobe ColdFusion 2018u17, 2021u7, and 2023u1 (and earlier) are affected by a deserialization of untrusted data flaw that can lead to arbitrary code e…KEVEPSS 97%analysed9.8CVE-2023-29300Adobe ColdFusion untrusted data deserialization allows code executionAdobe ColdFusion 2018u16 and earlier, 2021u6 and earlier, and 2023.0.0.330468 and earlier deserialize untrusted data, which can lead to arbitrary cod…KEVEPSS 100%analysed9.8CVE-2023-26359Adobe ColdFusion untrusted data deserialization allows code executionAdobe ColdFusion 2018 Update 15 and earlier and 2021 Update 5 and earlier deserialize untrusted data, which can lead to arbitrary code execution in t…KEVEPSS 17%analysed9.8CVE-2018-15961Adobe ColdFusion unrestricted file upload leads to code executionAdobe ColdFusion (July 12 release 2018.0.0.310739, Update 6 and earlier, and Update 14 and earlier) allows unrestricted file uploads. An uploaded fil…KEVEPSS 100%analysed9.8CVE-2018-4939Adobe ColdFusion Deserialization of Untrusted Data Enables Code ExecutionAdobe ColdFusion Update 5 and earlier and ColdFusion 11 Update 13 and earlier contain a deserialization of untrusted data flaw (CWE-502). A remote, u…KEVEPSS 62%analysed9.8CVE-2017-3066Adobe ColdFusion Java deserialization in Apache BlazeDS allows RCEAdobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 Update 11 and earlier, and ColdFusion 10 Update 22 and earlier contain a Java deserializati…KEVEPSS 91%analysed9.8CVE-2013-0632Adobe ColdFusion RDS default password authentication bypassAdobe ColdFusion 9.0 through 10 ships administrator.cfc with an RDS component that accepts a default empty password. An attacker can log in to RDS wi…KEVEPSS 94%analysed

Source: NIST National Vulnerability Database (record CVE-2010-2861), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.