Junglewise Threat Intelligence

CVE-2026-47906: Adobe Dreamweaver arbitrary code execution via vulnerable component

CVE-2026-47906 · Severity: high · CVSS 8.6 · Published 2026-06-09

Technologies: Adobe Dreamweaver. Vendors: Adobe.

Executive brief

Adobe Dreamweaver, a professional tool for web design and development, is affected by a security flaw in one of its underlying components. If a user is tricked into opening a specially crafted malicious file, an attacker could gain the ability to run unauthorized commands on the user's computer. This could lead to a full system compromise, data theft, or the installation of malware.

Technical details

Adobe Dreamweaver Desktop (versions 21.7 and earlier) contains a vulnerability categorized as a Dependency on Vulnerable Third-Party Component. The flaw exists because the application relies on an external library or module that contains a known security defect. An attacker can exploit this by convincing a user to open a malicious file, leading to arbitrary code execution in the context of the current user. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) indicates a local attack vector with a 'Changed' scope, suggesting the exploit can impact components beyond the immediate application environment. Users are advised to update to the latest version provided by Adobe.

Affected products

  • Adobe Dreamweaver Desktop 21.7 and earlier

Timeline

  • 2026-06-09: disclosed: Initial disclosure by Adobe and NVD publication.
  • 2026-06-09: advisory: Adobe security bulletin APSB26-62 released.

References

Related threats