
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47908 is an Access of Uninitialized Pointer vulnerability in Adobe Dreamweaver Desktop that could result in arbitrary code execution in the context of the current user. It affects Dreamweaver Desktop versions 21.7 and earlier on Windows and macOS. Adobe disclosed and patched the vulnerability on June 9, 2026, via security bulletin APSB26-62. It carries a CVSS v3.1 base score of 7.8 (High) (Adobe Advisory, GitHub Advisory).
The vulnerability is classified under CWE-824 (Access of Uninitialized Pointer) and CWE-863 (Incorrect Authorization). It arises when Dreamweaver Desktop processes a specially crafted malicious file, accessing a pointer that has not been properly initialized, which can lead to memory corruption and ultimately arbitrary code execution. The attack vector is local (AV:L), requires no privileges (PR:N), but does require user interaction — specifically, a victim must open a malicious file. No public proof-of-concept or technical write-up detailing the precise exploitation mechanics has been identified (Adobe Advisory, GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the current user running Dreamweaver Desktop, resulting in high impact to confidentiality, integrity, and availability. An attacker could read sensitive files accessible to the user, modify system data, or disrupt service availability. The scope is unchanged, meaning the impact is confined to the security context of the affected application and user account, limiting but not eliminating the risk of lateral movement depending on the user's privilege level (Adobe Advisory, GitHub Advisory).
cmd.exe, powershell.exe, bash, curl, or other shells/utilities).Adobe has released a patch addressing this vulnerability in Dreamweaver Desktop version 21.8, available via Adobe's update mechanism and security bulletin APSB26-62 (released June 9, 2026). Users should update to version 21.8 or later immediately. As interim mitigations, users should avoid opening Dreamweaver files from untrusted or unknown sources, and administrators should consider restricting file access permissions to limit the potential impact of exploitation (Adobe Advisory).
The vulnerability was noted in CISA's weekly vulnerability bulletin (SB26-166) and picked up by standard vulnerability tracking services including Tenable (Nessus plugin 320131), VulDB, and INCIBE-CERT. No significant independent researcher commentary, social media discussion, or media coverage beyond routine vulnerability aggregation has been identified for this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."