CVE-2026-47907
Adobe Dreamweaver vulnerability analysis and mitigation

Overview

CVE-2026-47907 is an Improper Access Control vulnerability in Adobe Dreamweaver Desktop versions 21.7 and earlier that enables arbitrary file system read access. An attacker can exploit this flaw to access sensitive files and directories outside the intended application scope, but exploitation requires a victim to open a malicious file. The vulnerability affects Dreamweaver Desktop on both Windows and macOS platforms. It was disclosed and patched on June 9, 2026, as part of Adobe security bulletin APSB26-62. The CVSS v3.1 base score is 6.3 (Medium) per NVD, though ENISA and the GitHub Advisory Database rate it as 8.2 (High) due to a changed scope with high confidentiality and integrity impact (Adobe Advisory, GitHub Advisory).

Technical details

The vulnerability is classified under CWE-284 (Improper Access Control) and CWE-20 (Improper Input Validation), indicating that Dreamweaver Desktop fails to properly restrict file system access when processing certain file types (GitHub Advisory). The attack vector is local, requiring low attack complexity and no privileges, but mandating user interaction — specifically, a victim must open a crafted malicious file. When the malicious file is opened, the application's access controls are bypassed, allowing reads of files and directories outside the intended scope (scope change). No public proof-of-concept or detailed technical write-up has been identified at this time (Adobe Advisory).

Impact

Successful exploitation allows an attacker to read arbitrary files and directories on the victim's system, including sensitive data outside the intended application scope, resulting in high confidentiality impact. The GitHub Advisory Database also notes a high integrity impact under its scoring, suggesting potential for data manipulation in addition to disclosure. Availability is not impacted. The changed scope indicates that resources beyond the vulnerable Dreamweaver component itself may be affected, potentially exposing credentials, configuration files, or other sensitive user data stored on the system (GitHub Advisory, Adobe Advisory).

Exploitation steps

  1. Craft a malicious file: An attacker creates a specially crafted file (e.g., a Dreamweaver project or supported document format) that, when opened, triggers the improper access control flaw to read files outside the intended scope.
  2. Deliver the malicious file: The attacker distributes the file to a target via phishing email, malicious download link, or other social engineering means, targeting users with Adobe Dreamweaver Desktop 21.7 or earlier installed.
  3. Victim opens the file: The victim opens the malicious file in Dreamweaver Desktop, triggering the vulnerability.
  4. Arbitrary file system read: The application's access controls fail to restrict file system access, allowing the attacker's payload to read sensitive files and directories outside the intended scope (e.g., credentials, configuration files, SSH keys).
  5. Exfiltrate data: Depending on the payload design, the accessed file contents may be transmitted to an attacker-controlled server or staged for retrieval (Adobe Advisory, GitHub Advisory).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited Dreamweaver project files (.dwt, .dw, or other supported formats) received via email or downloaded from untrusted sources.
  • Logs: Application logs showing Dreamweaver accessing file paths outside the user's project directory or web root; OS-level audit logs (e.g., Windows Security Event Log, macOS Unified Log) recording file read operations by the Dreamweaver process on sensitive directories (e.g., ~/.ssh/, %APPDATA%, /etc/).
  • Network: Unexpected outbound network connections from the Dreamweaver process to external IP addresses shortly after opening a file, potentially indicating data exfiltration.
  • Process: Dreamweaver spawning unexpected child processes or making unusual system calls to read files outside the project workspace.

Mitigation and workarounds

Adobe has released a security update (APSB26-62) addressing this vulnerability; users should update Adobe Dreamweaver Desktop to version 21.8 or later on both Windows and macOS (Adobe Advisory). As a workaround prior to patching, users should avoid opening Dreamweaver files received from untrusted or unknown sources. Organizations should also consider applying the principle of least privilege to limit the data accessible to the Dreamweaver process, reducing the potential impact of exploitation.

Community reactions

The vulnerability was noted in CISA's weekly vulnerability bulletin (SB26-166) and covered by security aggregators including BeyondMachines and Fortress SRM in their June 2026 threat roundups. Social media activity on Bluesky referenced the CVE shortly after disclosure. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability tracking and aggregation.

Additional resources


SourceThis report was generated using AI

Related Adobe Dreamweaver vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47907HIGH8.6
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026
CVE-2026-47906HIGH8.6
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026
CVE-2026-47908HIGH7.8
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026
CVE-2026-47910MEDIUM6.3
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026
CVE-2026-47909MEDIUM6.3
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management