
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47909 is an Improper Input Validation vulnerability in Adobe Dreamweaver Desktop that allows arbitrary file system read beyond the intended access scope. It affects Dreamweaver Desktop versions 21.7 and earlier on Windows and macOS platforms. The vulnerability was disclosed and patched on June 9, 2026, via Adobe Security Bulletin APSB26-62. It carries a CVSS v3.1 base score of 6.3 (Medium) (Adobe Advisory, GitHub Advisory).
The vulnerability is rooted in improper input validation (CWE-20) within Adobe Dreamweaver Desktop's file handling logic, which fails to adequately restrict file system access paths. The attack vector is local, requiring no privileges, but does require user interaction — specifically, a victim must open a malicious file crafted by the attacker. When the malicious file is opened, Dreamweaver processes unsanitized input that allows path traversal or similar techniques to read files and directories outside the application's intended scope, resulting in a scope change (Adobe Advisory, GitHub Advisory).
Successful exploitation results in unauthorized read access to arbitrary files and directories on the victim's file system, beyond the scope intended for Dreamweaver. The impact is limited to confidentiality — there is no integrity or availability impact — but sensitive files such as credentials, configuration files, SSH keys, or personal data could be exposed. Because the scope is marked as changed, resources outside the vulnerable component's security boundary may be accessed (Adobe Advisory, GitHub Advisory).
.ste, .dwsite, or similar) received via email or external sources; files containing path traversal sequences (e.g., ../, ..\) in project or configuration fields.~/.ssh/, C:\Users\<user>\AppData\, /etc/) not associated with any active project.Adobe has released a security update addressing this vulnerability; users should update Adobe Dreamweaver Desktop to version 21.8 or later, as versions 21.7 and earlier are affected on both Windows and macOS (Adobe Advisory). As a behavioral workaround, users should avoid opening Dreamweaver project or site files received from untrusted or unknown sources. Organizations should consider applying the update as part of their standard patch cycle given the medium severity and lack of active exploitation.
The vulnerability received routine coverage from vulnerability tracking services and security aggregators following Adobe's June 9, 2026 patch release, including mentions on Bluesky CVE feeds and security update roundups. Fortress SRM included it in their June 2026 threat and security update summary. No notable independent researcher commentary or significant media coverage has been identified beyond standard vulnerability database entries (Adobe Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."