
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47910 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Dreamweaver Desktop that allows arbitrary file system read operations outside the intended access scope. It affects Dreamweaver Desktop versions 21.7 and earlier (all versions prior to 21.8). The vulnerability was published on June 9, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 6.3 (Medium) (GitHub Advisory, Adobe Advisory).
The vulnerability stems from an incorrect authorization check (CWE-863) within Dreamweaver Desktop's file handling logic, which fails to properly restrict access to files and directories outside the intended scope when processing certain file types. An attacker exploits this by crafting a malicious file that, when opened by a victim, causes Dreamweaver to read arbitrary files from the local file system beyond its authorized access boundaries. The attack vector is local (AV:L), requires no privileges (PR:N), but does require user interaction (UI:R) — specifically, a victim must open the attacker-supplied malicious file. The scope is marked as Changed (S:C), indicating the vulnerability's impact extends beyond the vulnerable component itself (GitHub Advisory).
Successful exploitation results in high confidentiality impact, allowing an attacker to read sensitive files and directories on the victim's system that are outside the intended access scope of Dreamweaver. There is no integrity or availability impact. An attacker could potentially access credentials, configuration files, source code, or other sensitive data stored on the local file system, depending on the permissions of the running user account (GitHub Advisory, Adobe Advisory).
.dwt, .dw, or other supported formats) received via email or downloaded from untrusted sources.Dreamweaver.exe or equivalent) accessing files and directories outside typical project or web root directories (e.g., accessing %APPDATA%, %USERPROFILE%, system directories, or credential stores).Adobe has released a patch addressing this vulnerability; users should update Dreamweaver Desktop to version 21.8 or later. As an interim measure, users should avoid opening Dreamweaver files received from untrusted or unknown sources. Organizations should implement file access monitoring to detect unauthorized reads by the Dreamweaver process, and consider restricting Dreamweaver's access to sensitive directories via OS-level controls where feasible (Adobe Advisory, GitHub Advisory).
Coverage of CVE-2026-47910 has been limited to standard vulnerability aggregation and tracking platforms (VulnDB, CVEFeed, Tenable Nessus plugin 320131, INCIBE). Fortress SRM included it in their June 2026 threat and security update summary. No notable independent researcher commentary or significant social media discussion has been observed for this vulnerability (Fortress SRM).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."