CVE-2026-34619
HIGH
NVD
CVSS Score
7.7
Severity
HIGH
Published
Apr 14, 2026
Vendor
unknown
Description
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction.