Description
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-06-09
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Improper Access Control flaw in Adobe Dreamweaver Desktop allows a victim to read files from the local file system that fall outside the intended access scope. The vulnerability requires user interaction: the victim must open a crafted file. Once executed, the application’s read operations succeed and the attacker can retrieve sensitive data. The flaw manifests as a change in scope, meaning that operations originally confined to certain directories can now access higher‑level directories.

Affected Systems

Adobe Dreamweaver Desktop versions 21.7 and earlier are affected by this vulnerability. The application runs under the user’s account, so the files it can read depend on that account’s permissions. Files or directories that are normally outside the designated access scope can be accessed if the user opens a malicious file.

Risk and Exploitability

The CVSS score of 8.2 indicates a high‑severity risk. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that there is currently no widespread exploitation data. Attackers must employ social engineering to convince a user to open a malicious file, after which arbitrary read of privileged files is possible. The scope change enlarges the attacker’s reach within the local file system, potentially exposing confidential information.

Generated by OpenCVE AI on June 9, 2026 at 22:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dreamweaver Desktop to the latest version (at least 22.x) as released by Adobe.
  • If an update is not possible, restrict the ability to open potentially malicious files by using a sandbox, disabling FILE->OPEN for non‑admin users, or otherwise preventing untrusted file processing.
  • Ensure that the directories containing sensitive data are not readable by the accounts under which Dreamweaver operates, and monitor logs for unexpected file‑read activity.

Generated by OpenCVE AI on June 9, 2026 at 22:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 19:45:00 +0000

Type Values Removed Values Added
Description Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Dreamweaver Desktop | Improper Access Control (CWE-284)
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-06-09T19:24:07.503Z

Reserved: 2026-05-20T15:50:31.359Z

Link: CVE-2026-47907

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-09T20:16:59.803

Modified: 2026-06-09T20:16:59.803

Link: CVE-2026-47907

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T22:15:15Z

Weaknesses