CVE-2026-47906: Dreamweaver Desktop | Dependency on Vulnerable Third-Party Component (CWE-1395)
Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47906?
CVE-2026-47906 has a severity rating of 8.6, which is classified as high.
How do I fix CVE-2026-47906?
To fix CVE-2026-47906, update Adobe Dreamweaver Desktop to the latest version released after version 21.7.
What are the potential consequences of CVE-2026-47906?
CVE-2026-47906 can lead to arbitrary code execution in the context of the current user, posing significant security risks.
What versions of Adobe Dreamweaver are vulnerable to CVE-2026-47906?
Adobe Dreamweaver Desktop versions 21.7 and earlier are affected by CVE-2026-47906.
Does CVE-2026-47906 require user interaction for exploitation?
Yes, CVE-2026-47906 requires user interaction, specifically that the victim must open a malicious file to exploit the vulnerability.