Junglewise Threat Intelligence

CVE-2026-47910: Adobe Dreamweaver incorrect authorization arbitrary file read

CVE-2026-47910 · Severity: medium · CVSS 6.3 · Published 2026-06-09

Technologies: Adobe Dreamweaver. Vendors: Adobe.

Executive brief

Adobe Dreamweaver, a popular web development application, is affected by a security flaw that could allow unauthorized access to files on a user's computer. An attacker could trick a user into opening a specially crafted file, which then allows the attacker to read sensitive information and directories they should not have access to. This could lead to the exposure of private data or configuration files stored on the local system.

Technical details

Adobe Dreamweaver Desktop versions 21.7 and earlier contain an Incorrect Authorization vulnerability (CWE-863). The flaw exists in how the application handles file access permissions when processing specific file types. An attacker can exploit this by convincing a user to open a maliciously crafted file, leading to an arbitrary file system read. Because the vulnerability involves a 'Scope' change (S:C) in the CVSS metric, the impact extends beyond the application's immediate environment to the broader host file system. The attack requires local access to deliver the file and user interaction to trigger the read. Adobe has addressed this in security bulletin APSB26-62.

Affected products

  • Adobe Dreamweaver Desktop 21.7 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats