Executive brief
Adobe Dreamweaver is a web design and development application used by designers and developers to create websites and web applications. Versions 21.6 and earlier contain an input validation flaw that allows attackers to execute arbitrary code with the privileges of the user running Dreamweaver. An attacker must trick a user into opening a specially crafted malicious file to trigger the exploit.
Technical details
Dreamweaver Desktop versions 21.6 and earlier are vulnerable to improper input validation that fails to adequately sanitize user-supplied input, leading to arbitrary code execution. The vulnerability exists in the file processing component and requires user interaction—specifically, a victim must open a malicious file. An authenticated attacker (or unauthenticated attacker via social engineering) can craft a malicious file that, when opened in a vulnerable version of Dreamweaver, executes arbitrary code in the context of the current user. No remote exploitation vector is present; the file must be opened locally. Adobe has issued a security advisory (APSB26-01) with patched versions.
Affected products
- Adobe Dreamweaver 21.6 and earlier
Timeline
- 2026-01-13: disclosed