Executive brief
Adobe Dreamweaver is a professional web design and development tool used by designers and developers to build websites. Versions 21.6 and earlier contain a flaw that allows attackers to write arbitrary files to a victim's system if they open a malicious file, potentially leading to system compromise, data loss, or installation of malicious code.
Technical details
The vulnerability is an improper input validation flaw in Dreamweaver's file handling mechanism that allows arbitrary file system write operations. An attacker can craft a malicious file that, when opened by a user in Dreamweaver, bypasses input validation controls and writes arbitrary data to the filesystem. This requires user interaction (opening the malicious file) and the scope is changed, meaning the vulnerability impacts resources beyond the vulnerable component. The attack vector is local/user-initiated through file opening.
Affected products
- Adobe Dreamweaver 21.6 and earlier
Timeline
- 2026-01-13: disclosed
- other: Affects versions 21.6 and earlier; patched version not specified in advisory