ColdFusion is affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ColdFusion is affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. | |
| Title | ColdFusion | Improper Access Control (CWE-284) | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: adobe
Published: 2026-09-08T19:37:47.584Z
Updated: 2026-09-09T16:10:57.587Z
Reserved: 2026-08-18T18:44:22.496Z
Link: CVE-2026-75998
Updated: 2026-09-09T16:10:52.559Z
Status : Undergoing Analysis
Published: 2026-09-08T20:18:23.637
Modified: 2026-09-09T17:17:41.540
Link: CVE-2026-75998
No data.