
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CVE: CVE-2026-34619 PT ID: PT-2026-32934 Vendor: Adobe Product: ColdFusion CVSS: 7.7 Credits: n/a Description: ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-34619 • https://helpx.adobe.com/security/products/coldfusion/apsb26-38.html #dbugs_vuln
Post summary
The text announces the ColdFusion CVE-2026-34619, details its path traversal flaw, and references a vendor advisory with a patch.


