CVE-2026-21267

Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue requires user interaction in that a victim must open a malicious file and scope is changed.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:adobe:dreamweaver:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-13 19:16

Updated : 2026-01-14 20:51


NVD link : CVE-2026-21267

Mitre link : CVE-2026-21267

CVE.ORG link : CVE-2026-21267


JSON object : View

Products Affected

microsoft

  • windows

apple

  • macos

adobe

  • dreamweaver
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')