CVE-2026-21274 is an Incorrect Authorization vulnerability affecting Adobe Dreamweaver Desktop versions 21.6 and earlier on Windows and macOS, allowing for arbitrary code execution. This high-severity vulnerability (CVSS 7.8) requires user interaction, specifically opening a malicious file, to bypass security measures and execute unauthorized code, leading to potential complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, no public exploit code, and it's not on CISA's KEV catalog, the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 21.7CPE matchmatch criteria | cpe:2.3:a:adobe:dreamweaver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.