Vulnerability record · CVE-2022-38418 · published 14 October 2022
CVE-2022-38418: Adobe ColdFusion path traversal leads to arbitrary code execution
Adobe · Coldfusion
Adobe ColdFusion Update 14 and earlier, and Update 4 and earlier, contain a path traversal flaw (CWE-22) that allows an attacker to reach files outside the intended restricted directory. Successful exploitation results in arbitrary code execution in the context of the current user, making this a severe remote compromise risk for exposed ColdFusion servers.
Description
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and arbitrary code execution, combined with a very high EPSS score, makes this an urgent patch.
What it is
Adobe ColdFusion Update 14 and earlier, and Update 4 and earlier, contain a path traversal flaw (CWE-22) that allows an attacker to reach files outside the intended restricted directory. Successful exploitation results in arbitrary code execution in the context of the current user, making this a severe remote compromise risk for exposed ColdFusion servers.
Impact
An attacker can execute arbitrary code under the ColdFusion process account, potentially leading to full server compromise and data theft. No user interaction is required, so the victim does not need to open a file or click a link.
Attack surface
The CVSS vector AV:N/PR:N/UI:N indicates the flaw is reachable over the network with no authentication and no user interaction. Any internet- or network-exposed ColdFusion instance running an affected update level is a candidate target.
Exploitation
The record is not listed in CISA KEV and has no ransomware associations, but EPSS is very high at 0.80023 (99.6th percentile), indicating strong likelihood of exploitation activity. The only references are Adobe's patch advisory, so no public exploit details are confirmed in this record.
What to do
- Apply the Adobe ColdFusion security update referenced in APSB22-44 immediately, upgrading past Update 14 and Update 4.
- Restrict network access to ColdFusion administrative and application endpoints to trusted hosts only.
- Run the ColdFusion service under a low-privilege account with minimal filesystem permissions.
- Monitor and alert on unexpected file access or process creation originating from the ColdFusion service account.
Detection
- Review ColdFusion server logs for path traversal patterns such as ../ sequences in request URIs or parameters.
- Monitor for unexpected child processes spawned by the ColdFusion service (e.g., cmd.exe, powershell, /bin/sh).
- Alert on file reads or writes outside the ColdFusion web root by the service account.
- Correlate outbound network connections from the ColdFusion host with known malicious infrastructure.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/coldfusion/apsb22-44.html | PatchVendor Advisory |
| https://helpx.adobe.com/security/products/coldfusion/apsb22-44.html | PatchVendor Advisory |
Track CVE-2022-38418 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-38418), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.