Vulnerability record · CVE-2023-26361 · published 23 March 2023
CVE-2023-26361: Adobe ColdFusion path traversal allows arbitrary file read
Adobe · Coldfusion
Adobe ColdFusion 2018 Update 15 and earlier and 2021 Update 5 and earlier contain a path traversal flaw (CWE-22) that lets a pathname escape its restricted directory. It matters because it enables arbitrary file system reads on the server, and the affected versions are broad enough that unpatched ColdFusion instances remain exposed.
Description
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in Arbitrary file system read. Exploitation of this issue does not require user interaction, but does require administrator privileges.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Automated analysis
medium priorityThe flaw is a high-impact file read but requires administrator privileges, and CVSS rates it 4.9 medium despite a high EPSS score.
What it is
Adobe ColdFusion 2018 Update 15 and earlier and 2021 Update 5 and earlier contain a path traversal flaw (CWE-22) that lets a pathname escape its restricted directory. It matters because it enables arbitrary file system reads on the server, and the affected versions are broad enough that unpatched ColdFusion instances remain exposed.
Impact
An attacker with administrator privileges can read arbitrary files on the server file system, exposing configuration, credential and application data. There is no write or code execution impact described in the record.
Attack surface
Reachable over the network (AV:N) with no user interaction (UI:N), but it requires high privileges (PR:H), meaning an attacker must already hold a ColdFusion administrator account or equivalent access.
Exploitation
Not listed in CISA KEV and no ransomware use is documented; EPSS is high at roughly 0.587 (99th percentile), and the only references are Adobe's patch advisory, so no public exploit code is confirmed by this record.
What to do
- Apply the Adobe ColdFusion update referenced in advisory APSB23-25 to move past 2018 Update 15 and 2021 Update 5.
- Restrict and audit ColdFusion administrator accounts, enforcing least privilege and removing unused admin access.
- Limit network exposure of ColdFusion admin interfaces to trusted management networks.
- Monitor and rotate any credentials or secrets stored in files readable by the ColdFusion service account.
Detection
- Review ColdFusion server logs for path traversal patterns such as ../ sequences in file or template parameters.
- Alert on unexpected file read activity by the ColdFusion service account outside web roots and application directories.
- Audit administrator logins and actions for anomalous or off-hours access to file-handling features.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html | PatchVendor Advisory |
| https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html | PatchVendor Advisory |
Track CVE-2023-26361 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-26361), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.