CVE-2026-47910
Adobe Dreamweaver vulnerability analysis and mitigation

Overview

CVE-2026-47910 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Dreamweaver Desktop that allows arbitrary file system read operations outside the intended access scope. It affects Dreamweaver Desktop versions 21.7 and earlier (all versions prior to 21.8). The vulnerability was published on June 9, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 6.3 (Medium) (GitHub Advisory, Adobe Advisory).

Technical details

The vulnerability stems from an incorrect authorization check (CWE-863) within Dreamweaver Desktop's file handling logic, which fails to properly restrict access to files and directories outside the intended scope when processing certain file types. An attacker exploits this by crafting a malicious file that, when opened by a victim, causes Dreamweaver to read arbitrary files from the local file system beyond its authorized access boundaries. The attack vector is local (AV:L), requires no privileges (PR:N), but does require user interaction (UI:R) — specifically, a victim must open the attacker-supplied malicious file. The scope is marked as Changed (S:C), indicating the vulnerability's impact extends beyond the vulnerable component itself (GitHub Advisory).

Impact

Successful exploitation results in high confidentiality impact, allowing an attacker to read sensitive files and directories on the victim's system that are outside the intended access scope of Dreamweaver. There is no integrity or availability impact. An attacker could potentially access credentials, configuration files, source code, or other sensitive data stored on the local file system, depending on the permissions of the running user account (GitHub Advisory, Adobe Advisory).

Exploitation steps

  1. Craft a malicious file: Create a specially crafted file (e.g., a Dreamweaver project or supported document format) that, when parsed by Dreamweaver Desktop, triggers the incorrect authorization check and causes the application to read files outside its intended scope.
  2. Deliver the file to the victim: Use social engineering techniques (e.g., phishing email, malicious download link, or shared file) to convince the target user to download and open the malicious file in Dreamweaver Desktop.
  3. Trigger file system read: When the victim opens the malicious file in Dreamweaver Desktop (versions 21.7 or earlier), the authorization bypass is triggered, allowing the application to access sensitive files and directories outside the intended scope.
  4. Exfiltrate data: The attacker's malicious file may include mechanisms (e.g., embedded references or callbacks) to relay the contents of accessed files back to an attacker-controlled server, resulting in data exfiltration (GitHub Advisory).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited Dreamweaver project files (.dwt, .dw, or other supported formats) received via email or downloaded from untrusted sources.
  • Logs: Application or OS-level file access logs showing Dreamweaver Desktop (Dreamweaver.exe or equivalent) accessing files and directories outside typical project or web root directories (e.g., accessing %APPDATA%, %USERPROFILE%, system directories, or credential stores).
  • Network: Unexpected outbound network connections from the Dreamweaver process to external IP addresses shortly after opening a file, which may indicate data exfiltration via an embedded callback in the malicious file.
  • Process: Dreamweaver Desktop process exhibiting unusual file read activity across sensitive directories not associated with any open project.

Mitigation and workarounds

Adobe has released a patch addressing this vulnerability; users should update Dreamweaver Desktop to version 21.8 or later. As an interim measure, users should avoid opening Dreamweaver files received from untrusted or unknown sources. Organizations should implement file access monitoring to detect unauthorized reads by the Dreamweaver process, and consider restricting Dreamweaver's access to sensitive directories via OS-level controls where feasible (Adobe Advisory, GitHub Advisory).

Community reactions

Coverage of CVE-2026-47910 has been limited to standard vulnerability aggregation and tracking platforms (VulnDB, CVEFeed, Tenable Nessus plugin 320131, INCIBE). Fortress SRM included it in their June 2026 threat and security update summary. No notable independent researcher commentary or significant social media discussion has been observed for this vulnerability (Fortress SRM).

Additional resources


SourceThis report was generated using AI

Related Adobe Dreamweaver vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47907HIGH8.6
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026
CVE-2026-47906HIGH8.6
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026
CVE-2026-47908HIGH7.8
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026
CVE-2026-47910MEDIUM6.3
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026
CVE-2026-47909MEDIUM6.3
  • Adobe Dreamweaver logoAdobe Dreamweaver
  • cpe:2.3:a:adobe:dreamweaver
NoYesJun 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management