
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47907 is an Improper Access Control vulnerability in Adobe Dreamweaver Desktop versions 21.7 and earlier that enables arbitrary file system read access. An attacker can exploit this flaw to access sensitive files and directories outside the intended application scope, but exploitation requires a victim to open a malicious file. The vulnerability affects Dreamweaver Desktop on both Windows and macOS platforms. It was disclosed and patched on June 9, 2026, as part of Adobe security bulletin APSB26-62. The CVSS v3.1 base score is 6.3 (Medium) per NVD, though ENISA and the GitHub Advisory Database rate it as 8.2 (High) due to a changed scope with high confidentiality and integrity impact (Adobe Advisory, GitHub Advisory).
The vulnerability is classified under CWE-284 (Improper Access Control) and CWE-20 (Improper Input Validation), indicating that Dreamweaver Desktop fails to properly restrict file system access when processing certain file types (GitHub Advisory). The attack vector is local, requiring low attack complexity and no privileges, but mandating user interaction — specifically, a victim must open a crafted malicious file. When the malicious file is opened, the application's access controls are bypassed, allowing reads of files and directories outside the intended scope (scope change). No public proof-of-concept or detailed technical write-up has been identified at this time (Adobe Advisory).
Successful exploitation allows an attacker to read arbitrary files and directories on the victim's system, including sensitive data outside the intended application scope, resulting in high confidentiality impact. The GitHub Advisory Database also notes a high integrity impact under its scoring, suggesting potential for data manipulation in addition to disclosure. Availability is not impacted. The changed scope indicates that resources beyond the vulnerable Dreamweaver component itself may be affected, potentially exposing credentials, configuration files, or other sensitive user data stored on the system (GitHub Advisory, Adobe Advisory).
.dwt, .dw, or other supported formats) received via email or downloaded from untrusted sources.~/.ssh/, %APPDATA%, /etc/).Adobe has released a security update (APSB26-62) addressing this vulnerability; users should update Adobe Dreamweaver Desktop to version 21.8 or later on both Windows and macOS (Adobe Advisory). As a workaround prior to patching, users should avoid opening Dreamweaver files received from untrusted or unknown sources. Organizations should also consider applying the principle of least privilege to limit the data accessible to the Dreamweaver process, reducing the potential impact of exploitation.
The vulnerability was noted in CISA's weekly vulnerability bulletin (SB26-166) and covered by security aggregators including BeyondMachines and Fortress SRM in their June 2026 threat roundups. Social media activity on Bluesky referenced the CVE shortly after disclosure. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability tracking and aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."