Executive brief
Adobe Dreamweaver, a popular web development tool, is affected by a security flaw that could allow an attacker to read sensitive files on a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. This could lead to the unauthorized exposure of private data or configuration files, potentially compromising the user's system or other web projects.
Technical details
An improper access control vulnerability (CWE-284) exists in Adobe Dreamweaver Desktop versions 21.7 and earlier. The flaw allows for an arbitrary file system read, enabling an attacker to access sensitive files and directories outside of the application's intended scope. Exploitation requires local access and user interaction, specifically requiring a victim to open a malicious file provided by the attacker. The CVSS score of 8.2 reflects a 'Changed' scope, indicating the vulnerability allows the attacker to impact components beyond the security scope of the Dreamweaver application itself. Adobe has addressed this in security bulletin APSB26-62.
Affected products
- Adobe Dreamweaver Desktop 21.7 and earlier
Timeline
- 2026-06-09: advisory: Adobe published security bulletin APSB26-62 and NVD entry created.