Executive brief
Adobe Dreamweaver, a popular web development application, is affected by a security flaw that could allow an attacker to read sensitive files on a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file within the Dreamweaver application. This could result in the unauthorized exposure of private data or system configuration files.
Technical details
An Improper Input Validation vulnerability (CWE-20) exists in Adobe Dreamweaver Desktop versions 21.7 and earlier. The flaw allows for an arbitrary file system read when the application fails to properly validate input from a file opened by the user. An attacker can exploit this by crafting a malicious file that, when opened, leverages the changed scope (S:C) to access sensitive information outside of the application's intended directory constraints. This is a local attack vector requiring user interaction (UI:R) but no prior privileges (PR:N). Adobe has addressed this in security bulletin APSB26-62.
Affected products
- Adobe Dreamweaver Desktop 21.7 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Adobe security bulletin APSB26-62 published