Junglewise Threat Intelligence

CVE-2026-21267: Adobe Dreamweaver OS command injection

CVE-2026-21267 · Severity: high · CVSS 8.6 · Published 2026-01-13

Technologies: Apple macOS, Microsoft Windows, Adobe Dreamweaver. Vendors: Apple, Microsoft, Adobe.

Executive brief

Dreamweaver is a web development and design tool used by professionals to create and edit websites. Versions 21.6 and earlier contain a command injection flaw that allows attackers to execute arbitrary code on a developer's computer when a malicious file is opened, potentially compromising the system and any projects or data stored on it.

Technical details

Dreamweaver Desktop versions 21.6 and earlier are vulnerable to OS command injection through improper neutralization of special elements used in OS commands. The vulnerability can be exploited via a malicious file that, when opened by a user, causes the application to execute arbitrary OS commands with the privileges of the user running Dreamweaver. Exploitation requires user interaction (opening a crafted file). An attacker can achieve arbitrary code execution on the affected system. Patches for versions above 21.6 are available.

Affected products

  • Adobe Dreamweaver 21.6 and earlier

Timeline

  • 2026-01-13: disclosed

References

Related threats