Junglewise Threat Intelligence

CVE-2026-21272: Adobe Dreamweaver improper input validation in file handling

CVE-2026-21272 · Severity: high · CVSS 8.6 · Published 2026-01-13

Technologies: Apple macOS, Microsoft Windows, Adobe Dreamweaver. Vendors: Apple, Microsoft, Adobe.

Executive brief

Adobe Dreamweaver is a professional web design and development tool used by designers and developers to build websites. Versions 21.6 and earlier contain a flaw that allows attackers to write arbitrary files to a victim's system if they open a malicious file, potentially leading to system compromise, data loss, or installation of malicious code.

Technical details

The vulnerability is an improper input validation flaw in Dreamweaver's file handling mechanism that allows arbitrary file system write operations. An attacker can craft a malicious file that, when opened by a user in Dreamweaver, bypasses input validation controls and writes arbitrary data to the filesystem. This requires user interaction (opening the malicious file) and the scope is changed, meaning the vulnerability impacts resources beyond the vulnerable component. The attack vector is local/user-initiated through file opening.

Affected products

  • Adobe Dreamweaver 21.6 and earlier

Timeline

  • 2026-01-13: disclosed
  • other: Affects versions 21.6 and earlier; patched version not specified in advisory

References

Related threats