
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21272 is an Improper Input Validation vulnerability in Adobe Dreamweaver Desktop that could lead to arbitrary file system write. Affected versions include Dreamweaver Desktop 21.6 and earlier on Windows and macOS; version 21.7 resolves the issue. The vulnerability was disclosed on January 13, 2026, with an initial patch advisory (APSB26-01) published the same day and a follow-up advisory (APSB26-62) released on June 9, 2026. It carries a CVSS v3.1 base score of 8.6 (High), assigned by Adobe, with a changed scope reflecting potential impact beyond the vulnerable component (Adobe Advisory APSB26-01, Adobe Advisory APSB26-62).
The vulnerability is classified under CWE-20 (Improper Input Validation) and additionally associated with CWE-863 (Incorrect Authorization). The attack vector is local, requiring no privileges but necessitating user interaction — specifically, a victim must open a specially crafted malicious file within Dreamweaver Desktop. When the malicious file is processed, insufficient input validation allows an attacker to write arbitrary data to files on the file system, potentially injecting malicious content into existing files. The changed scope (S:C) in the CVSS vector indicates that exploitation can affect resources beyond the vulnerable Dreamweaver application itself (Adobe Advisory APSB26-01, Feedly Intelligence).
Successful exploitation results in high impact to confidentiality, integrity, and availability, as reflected in the CVSS scoring. An attacker can write or inject malicious data into arbitrary files on the victim's system, which could facilitate code execution, persistence mechanisms, or corruption of critical system or application files. Because the scope is changed, the impact can extend beyond the Dreamweaver application to other components or resources on the host system (Adobe Advisory APSB26-01).
Dreamweaver.exe on Windows or Adobe Dreamweaver on macOS) performing file write operations to atypical locations outside normal project directories.Adobe has released patched versions addressing this vulnerability: users should update Adobe Dreamweaver Desktop to version 21.7 or later, available via the Adobe Creative Cloud desktop application or the Adobe update mechanism. The initial patch was made available on January 13, 2026 (APSB26-01), with a follow-up security update released on June 9, 2026 (APSB26-62) covering versions 21.7 and earlier. As a workaround prior to patching, users should avoid opening Dreamweaver project files or documents received from untrusted or unknown sources. User awareness training regarding the risks of opening files from unverified origins is also recommended (Adobe Advisory APSB26-01, Adobe Advisory APSB26-62).
The Center for Internet Security (CIS) published an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution, recommending prompt patching (CIS Advisory). The Zero Day Initiative included this vulnerability in their January 2026 security update review. Community and social media discussion was limited, consistent with the low EPSS score and absence of public exploit code.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."