CVE-2026-47906
Adobe Dreamweaver vulnerability analysis and mitigation

Overview

CVE-2026-47906 is a Dependency on Vulnerable Third-Party Component vulnerability in Adobe Dreamweaver Desktop that can result in arbitrary code execution in the context of the current user. It affects Dreamweaver Desktop versions 21.7 and earlier on Windows and macOS. Adobe disclosed and patched the vulnerability on June 9, 2026. It carries a CVSS v3.1 base score of 8.6 (High) with a changed scope, reflecting potential impact beyond the vulnerable component itself (Adobe Advisory, GitHub Advisory).

Technical details

The root cause is a dependency on a vulnerable third-party component bundled within Adobe Dreamweaver Desktop (no specific CWE is assigned, but the vulnerability class corresponds to use of a vulnerable third-party library). The attack vector is local, requiring no privileges, but does require user interaction — specifically, a victim must open a malicious file crafted to trigger the vulnerable component. The changed scope indicates that successful exploitation can affect resources or processes beyond the Dreamweaver application itself. No specific technical write-ups or public proof-of-concept code have been identified at this time (Adobe Advisory, GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary code with the privileges of the user running Dreamweaver Desktop, resulting in high impact to confidentiality, integrity, and availability. The changed scope means the attacker may be able to affect resources outside the Dreamweaver process boundary, potentially enabling further lateral movement or privilege escalation on the host system. Sensitive data accessible to the current user — including project files, credentials stored locally, and system resources — could be exposed or tampered with (Adobe Advisory, GitHub Advisory).

Exploitation steps

  1. Craft a malicious file: An attacker creates a specially crafted file (e.g., a project file or document type supported by Dreamweaver) designed to trigger the vulnerable third-party component bundled with Dreamweaver Desktop versions 21.7 and earlier.
  2. Deliver the file: The attacker distributes the malicious file via phishing email, a compromised website, or other social engineering channels targeting Dreamweaver users.
  3. Victim opens the file: The victim opens the malicious file using Adobe Dreamweaver Desktop, triggering the vulnerable third-party component.
  4. Arbitrary code execution: The vulnerable component processes the malicious file and executes attacker-controlled code in the context of the current user, potentially spawning a shell, installing malware, or exfiltrating data (Adobe Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by the Dreamweaver Desktop process (e.g., cmd.exe, powershell.exe, bash, curl, or scripting interpreters) shortly after a file is opened.
  • File System: Unexpected files written to the user's temp directory, Dreamweaver installation directory, or startup folders following a Dreamweaver session; new or modified scripts or executables in user-writable locations.
  • Network: Unusual outbound network connections originating from the Dreamweaver process or its child processes to unknown external IP addresses or domains.
  • Logs: Application event log entries or crash reports associated with Dreamweaver around the time of file opening; unexpected process creation events logged by endpoint detection tools tied to the Dreamweaver parent process.

Mitigation and workarounds

Adobe has released a security update addressing this vulnerability; users should update Adobe Dreamweaver Desktop to version 21.8 or later, which is the first version not affected (versions prior to 21.8 are vulnerable) (Adobe Advisory). As an interim workaround until patching is possible, users should avoid opening Dreamweaver project files or other supported file types received from untrusted or unknown sources. Organizations should also consider applying application allowlisting or endpoint detection controls to monitor for unexpected child processes spawned by Dreamweaver.

Community reactions

The vulnerability received routine coverage from security aggregators and vulnerability tracking services following Adobe's June 9, 2026 patch release, including mentions on Bluesky, Mastodon, and security news outlets such as The Hacker Wire (The Hacker Wire). CISA included it in its weekly vulnerability bulletin (SB26-166). No notable independent researcher commentary or significant community debate has been identified beyond standard patch-day reporting.

Additional resources


SourceThis report was generated using AI

Related Adobe Dreamweaver vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47907HIGH8.6
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026
CVE-2026-47906HIGH8.6
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026
CVE-2026-47908HIGH7.8
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026
CVE-2026-47910MEDIUM6.3
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026
CVE-2026-47909MEDIUM6.3
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management