Junglewise Threat Intelligence

CVE-2026-47907: Adobe Dreamweaver improper access control arbitrary file read

CVE-2026-47907 · Severity: high · CVSS 8.2 · Published 2026-06-09

Technologies: Adobe Dreamweaver. Vendors: Adobe.

Executive brief

Adobe Dreamweaver, a popular web development tool, is affected by a security flaw that could allow an attacker to read sensitive files on a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. This could lead to the unauthorized exposure of private data or configuration files, potentially compromising the user's system or other web projects.

Technical details

An improper access control vulnerability (CWE-284) exists in Adobe Dreamweaver Desktop versions 21.7 and earlier. The flaw allows for an arbitrary file system read, enabling an attacker to access sensitive files and directories outside of the application's intended scope. Exploitation requires local access and user interaction, specifically requiring a victim to open a malicious file provided by the attacker. The CVSS score of 8.2 reflects a 'Changed' scope, indicating the vulnerability allows the attacker to impact components beyond the security scope of the Dreamweaver application itself. Adobe has addressed this in security bulletin APSB26-62.

Affected products

  • Adobe Dreamweaver Desktop 21.7 and earlier

Timeline

  • 2026-06-09: advisory: Adobe published security bulletin APSB26-62 and NVD entry created.

References

Related threats