Description
Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Lightroom Classic has an out‑of‑bounds write that allows an attacker to run code with the privileges of the user. The flaw is triggered when the application processes a specially crafted file, potentially enabling arbitrary instruction execution. The impact is execution of arbitrary code in the user context.

Affected Systems

Adobe Lightroom Classic is affected; all installations that have not applied the security update released in the Adobe advisory remain vulnerable. The advisory does not list specific version numbers, so any unpatched installation is considered impacted.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires user interaction – a victim must open a malicious file – so the attack can only occur when the user receives or opens a file that the attacker can control. While no public exploit is known, a determined adversary could craft a file to exploit the flaw.

Generated by OpenCVE AI on August 12, 2026 at 13:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the most recent Adobe security update for Lightroom Classic.
  • Educate users to avoid opening files from unknown or untrusted sources and verify the file’s origin before opening.
  • Consider implementing application whitelisting or file‑type restrictions to limit the ability of the application to process potentially malicious files.

Generated by OpenCVE AI on August 12, 2026 at 13:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe lightroom
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:lightroom:*:*:*:*:classic:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe lightroom
Microsoft
Microsoft windows

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe lightroom Classic
Vendors & Products Adobe
Adobe lightroom Classic

Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Lightroom Classic | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Lightroom Lightroom Classic
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:33:57.645Z

Reserved: 2026-05-21T15:28:38.144Z

Link: CVE-2026-48404

cve-icon Vulnrichment

Updated: 2026-08-11T20:00:31.134Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T18:17:29.573

Modified: 2026-08-28T00:17:57.633

Link: CVE-2026-48404

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:50:26Z

Weaknesses