
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47906 is a Dependency on Vulnerable Third-Party Component vulnerability in Adobe Dreamweaver Desktop that can result in arbitrary code execution in the context of the current user. It affects Dreamweaver Desktop versions 21.7 and earlier on Windows and macOS. Adobe disclosed and patched the vulnerability on June 9, 2026. It carries a CVSS v3.1 base score of 8.6 (High) with a changed scope, reflecting potential impact beyond the vulnerable component itself (Adobe Advisory, GitHub Advisory).
The root cause is a dependency on a vulnerable third-party component bundled within Adobe Dreamweaver Desktop (no specific CWE is assigned, but the vulnerability class corresponds to use of a vulnerable third-party library). The attack vector is local, requiring no privileges, but does require user interaction — specifically, a victim must open a malicious file crafted to trigger the vulnerable component. The changed scope indicates that successful exploitation can affect resources or processes beyond the Dreamweaver application itself. No specific technical write-ups or public proof-of-concept code have been identified at this time (Adobe Advisory, GitHub Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the user running Dreamweaver Desktop, resulting in high impact to confidentiality, integrity, and availability. The changed scope means the attacker may be able to affect resources outside the Dreamweaver process boundary, potentially enabling further lateral movement or privilege escalation on the host system. Sensitive data accessible to the current user — including project files, credentials stored locally, and system resources — could be exposed or tampered with (Adobe Advisory, GitHub Advisory).
cmd.exe, powershell.exe, bash, curl, or scripting interpreters) shortly after a file is opened.Adobe has released a security update addressing this vulnerability; users should update Adobe Dreamweaver Desktop to version 21.8 or later, which is the first version not affected (versions prior to 21.8 are vulnerable) (Adobe Advisory). As an interim workaround until patching is possible, users should avoid opening Dreamweaver project files or other supported file types received from untrusted or unknown sources. Organizations should also consider applying application allowlisting or endpoint detection controls to monitor for unexpected child processes spawned by Dreamweaver.
The vulnerability received routine coverage from security aggregators and vulnerability tracking services following Adobe's June 9, 2026 patch release, including mentions on Bluesky, Mastodon, and security news outlets such as The Hacker Wire (The Hacker Wire). CISA included it in its weekly vulnerability bulletin (SB26-166). No notable independent researcher commentary or significant community debate has been identified beyond standard patch-day reporting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."