Junglewise Threat Intelligence

CVE-2026-47908: Adobe Dreamweaver uninitialized pointer access in Desktop

CVE-2026-47908 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Adobe Dreamweaver. Vendors: Adobe.

Executive brief

Adobe Dreamweaver, a popular web development application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. If successful, the attacker could run unauthorized software or access sensitive data with the same permissions as the logged-in user.

Technical details

Adobe Dreamweaver Desktop versions 21.7 and earlier contain an Access of Uninitialized Pointer vulnerability (CWE-824). The flaw occurs when the application attempts to access memory through a pointer that has not been properly initialized, leading to memory corruption. An attacker can exploit this by providing a specially crafted file that, when opened by the user, triggers the vulnerability. Successful exploitation allows for arbitrary code execution in the context of the current user. The attack requires local access to deliver the file and user interaction to open it. Adobe has addressed this in newer versions, and users are advised to update to the latest release.

Affected products

  • Adobe Dreamweaver Desktop 21.7 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats