Junglewise Threat Intelligence

CVE-2026-21274: Adobe Dreamweaver Desktop incorrect authorization leading to code execution

CVE-2026-21274 · Severity: high · CVSS 7.8 · Published 2026-01-13

Technologies: Apple macOS, Microsoft Windows, Adobe Dreamweaver. Vendors: Adobe, Apple, Microsoft.

Executive brief

Adobe Dreamweaver Desktop is a web development tool used by professionals to create and edit websites. Versions 21.6 and earlier contain an authorization flaw that allows attackers to execute arbitrary code on a victim's computer when the user opens a malicious file, potentially compromising sensitive projects and system security.

Technical details

The vulnerability is classified as an Incorrect Authorization issue in Adobe Dreamweaver Desktop versions 21.6 and earlier. The flaw permits attackers to bypass security controls and execute unauthorized code in the context of the current user. Exploitation requires user interaction—specifically, a victim must open a specially crafted malicious file. This attack vector makes it suitable for social engineering campaigns. An attacker exploiting this vulnerability can achieve arbitrary code execution with the privileges of the compromised user account. Patches are expected to be available through Adobe's security advisory APSB26-01.

Affected products

  • Adobe Dreamweaver Desktop 21.6 and earlier

Timeline

  • 2026-01-13: disclosed

References

Related threats