Description
Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-08-11
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in Adobe Lightroom Classic’s handling of serialized data. When the application deserializes content provided by an untrusted source, it can trigger arbitrary code execution within the context of the user’s account. An attacker who supplies a crafted file can achieve full compromise of that user’s machine, including data loss, tampering, or persistence. The flaw is classified as CWE‑502 and the associated CVSS score of 8.6 highlights a high severity.

Affected Systems

It affects Adobe Lightroom Classic across all affected releases, although specific version numbers are not disclosed in the advisory. Users who continue to run legacy or unpatched copies of Lightroom Classic remain vulnerable until the security update is applied.

Risk and Exploitability

Exploitation requires the victim to open a malicious file, implying a user‑interaction attack. The CVSS score of 8.6 indicates that the weakness is exploitable even with limited privileges. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw permits code execution, the risk remains significant, especially in environments where users handle externally sourced images.

Generated by OpenCVE AI on August 12, 2026 at 12:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Lightroom Classic update that contains the deserialization fix.
  • Limit file access by restricting Lightroom’s import paths to trusted directories only, thereby reducing the chance that a malicious file is opened inadvertently.
  • Employ an endpoint security solution to scan image files for malicious payloads before they are processed by Lightroom.

Generated by OpenCVE AI on August 12, 2026 at 12:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe lightroom
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:lightroom:*:*:*:*:classic:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe lightroom
Microsoft
Microsoft windows

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe lightroom Classic
Vendors & Products Adobe
Adobe lightroom Classic

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Lightroom Classic | Deserialization of Untrusted Data (CWE-502)
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Lightroom Lightroom Classic
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:08.815Z

Reserved: 2026-05-21T15:28:38.143Z

Link: CVE-2026-48397

cve-icon Vulnrichment

Updated: 2026-08-12T13:35:52.384Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T18:17:29.427

Modified: 2026-08-28T00:17:57.390

Link: CVE-2026-48397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:50:20Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data