Description
Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Lightroom Classic includes an integer overflow or wraparound flaw that allows arbitrary code execution when a malicious file is opened. The flaw is identified as CWE‑190. Exploitation requires the victim to interact with the file, meaning the code runs with the privileges of the current user.

Affected Systems

Adobe Lightroom Classic is affected. No specific product versions are listed; the advisory does not provide version ranges, so all installations of Lightroom Classic remain potentially vulnerable until patched or otherwise secured.

Risk and Exploitability

The CVSS score of 7.8 demonstrates a high severity impact. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Exfiltration or sabotage could proceed if a user opens a crafted file, but exploitation requires the user to interact with the file, limiting the attack surface to social‑engineering or compromised media scenarios.

Generated by OpenCVE AI on August 12, 2026 at 13:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Adobe’s official security advisory for the latest patch and install it immediately.
  • Ensure Lightroom Classic is updated to the most recent version where the integer overflow issue is fixed.
  • If a patch cannot be applied immediately, block or quarantine suspicious files and require trusted source verification before opening them.

Generated by OpenCVE AI on August 12, 2026 at 13:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe lightroom
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:lightroom:*:*:*:*:classic:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe lightroom
Microsoft
Microsoft windows

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe lightroom Classic
Vendors & Products Adobe
Adobe lightroom Classic

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Lightroom Classic | Integer Overflow or Wraparound (CWE-190)
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Lightroom Lightroom Classic
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:04.859Z

Reserved: 2026-05-20T15:50:31.362Z

Link: CVE-2026-47940

cve-icon Vulnrichment

Updated: 2026-08-12T13:35:57.370Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T18:17:27.267

Modified: 2026-08-28T00:17:32.660

Link: CVE-2026-47940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:50:30Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound