Description
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-06-09
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Improper Access Control flaw (CWE-284) in Adobe Dreamweaver Desktop versions 21.7 and earlier could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code by having a victim open a malicious file, as the flaw requires user interaction. The vulnerability also changes scope, meaning that operations originally confined to certain directories can now access higher-level directories, potentially allowing the attacker to reach further into the local file system.

Affected Systems

Adobe Dreamweaver Desktop versions 21.7 and earlier are affected. The application runs under the user’s account, so the files it can read depend on that account’s permissions. Files or directories normally outside the designated access scope can be accessed if the user opens a malicious file.

Risk and Exploitability

The CVSS score of 8.6 indicates a high‑severity risk. The EPSS score is low (<1%), and the vulnerability is not listed in CISA’s KEV catalog, suggesting that there is currently no widespread exploitation data. Attackers must employ social engineering to convince a user to open a malicious file, after which arbitrary code execution is possible. The scope change enlarges the attacker’s reach within the local file system, potentially allowing the attacker to run privileged code and access sensitive data.

Generated by OpenCVE AI on June 24, 2026 at 09:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dreamweaver Desktop to the latest version (at least 22.x) as released by Adobe.
  • If an update is not possible, restrict the ability to open potentially malicious files by using a sandbox, disabling FILE->OPEN for non‑admin users, or otherwise preventing untrusted file processing.
  • Ensure that the directories containing sensitive data are not readable by the accounts under which Dreamweaver operates, and monitor logs for unexpected file‑read activity.

Generated by OpenCVE AI on June 24, 2026 at 09:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 23 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Description Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}

cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Thu, 11 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Microsoft
Microsoft windows
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:adobe:dreamweaver:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Microsoft
Microsoft windows

Wed, 10 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe dreamweaver
Vendors & Products Adobe
Adobe dreamweaver

Wed, 10 Jun 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 19:45:00 +0000

Type Values Removed Values Added
Description Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Dreamweaver Desktop | Improper Access Control (CWE-284)
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-06-23T21:13:19.130Z

Reserved: 2026-05-20T15:50:31.359Z

Link: CVE-2026-47907

cve-icon Vulnrichment

Updated: 2026-06-10T10:07:10.980Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T20:16:59.803

Modified: 2026-06-11T19:21:51.290

Link: CVE-2026-47907

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-24T09:45:14Z

Weaknesses