CVE-2026-47908
Adobe Dreamweaver vulnerability analysis and mitigation

Overview

CVE-2026-47908 is an Access of Uninitialized Pointer vulnerability in Adobe Dreamweaver Desktop that could result in arbitrary code execution in the context of the current user. It affects Dreamweaver Desktop versions 21.7 and earlier on Windows and macOS. Adobe disclosed and patched the vulnerability on June 9, 2026, via security bulletin APSB26-62. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, GitHub Advisory).

Technical details

The vulnerability is classified under CWE-824 (Access of Uninitialized Pointer) and CWE-863 (Incorrect Authorization). It arises when Dreamweaver Desktop processes a specially crafted malicious file, accessing a pointer that has not been properly initialized, which can lead to memory corruption and ultimately arbitrary code execution. The attack vector is local (AV:L), requires no privileges (PR:N), but does require user interaction — specifically, a victim must open a malicious file. No public proof-of-concept or technical write-up detailing the precise exploitation mechanics has been identified (Adobe Advisory, GitHub Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the current user running Dreamweaver Desktop, resulting in high impact to confidentiality, integrity, and availability. An attacker could read sensitive files accessible to the user, modify system data, or disrupt service availability. The scope is unchanged, meaning the impact is confined to the security context of the affected application and user account, limiting but not eliminating the risk of lateral movement depending on the user's privilege level (Adobe Advisory, GitHub Advisory).

Exploitation steps

  1. Craft a malicious file: An attacker creates a specially crafted file (e.g., a web project file or supported Dreamweaver format) designed to trigger the uninitialized pointer access when parsed by Dreamweaver Desktop.
  2. Deliver the file to the victim: The attacker distributes the malicious file via phishing email, malicious download link, or other social engineering methods targeting Dreamweaver users.
  3. Victim opens the file: The victim opens the malicious file in Adobe Dreamweaver Desktop version 21.7 or earlier, triggering the vulnerable code path.
  4. Uninitialized pointer accessed: Dreamweaver accesses an uninitialized pointer during file parsing, causing memory corruption.
  5. Arbitrary code execution: The memory corruption is leveraged to redirect execution flow, achieving arbitrary code execution in the context of the current user's privileges (Adobe Advisory, GitHub Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by the Dreamweaver Desktop process (e.g., cmd.exe, powershell.exe, bash, curl, or other shells/utilities).
  • File System: Unexpected files written to user-accessible directories (temp folders, AppData, or home directories) shortly after opening a Dreamweaver file; presence of unfamiliar scripts or executables.
  • Network: Unusual outbound network connections originating from the Dreamweaver process to unknown external IP addresses or domains following file open events.
  • Logs: Application crash logs or Windows Event Logs showing access violations or abnormal termination of Dreamweaver Desktop; security logs recording new process creation by Dreamweaver.

Mitigation and workarounds

Adobe has released a patch addressing this vulnerability in Dreamweaver Desktop version 21.8, available via Adobe's update mechanism and security bulletin APSB26-62 (released June 9, 2026). Users should update to version 21.8 or later immediately. As interim mitigations, users should avoid opening Dreamweaver files from untrusted or unknown sources, and administrators should consider restricting file access permissions to limit the potential impact of exploitation (Adobe Advisory).

Community reactions

The vulnerability was noted in CISA's weekly vulnerability bulletin (SB26-166) and picked up by standard vulnerability tracking services including Tenable (Nessus plugin 320131), VulDB, and INCIBE-CERT. No significant independent researcher commentary, social media discussion, or media coverage beyond routine vulnerability aggregation has been identified for this CVE.

Additional resources


SourceThis report was generated using AI

Related Adobe Dreamweaver vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47907HIGH8.6
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026
CVE-2026-47906HIGH8.6
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026
CVE-2026-47908HIGH7.8
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026
CVE-2026-47910MEDIUM6.3
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026
CVE-2026-47909MEDIUM6.3
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management