Description
Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Lightroom Classic contains an out‑of‑bounds write that can lead to arbitrary code execution when a user opens a malicious file. The flaw is a classic memory corruption vulnerability classified as CWE‑787. Because the exploit relies on a malicious file being opened, the attacker must have some level of user interaction, and the breach would occur in the context of the current user with whatever privileges that user holds.

Affected Systems

Adobe Lightroom Classic. No specific affected versions are provided in the data.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. EPSS is not available and the issue is not listed in the CISA KEV catalog, suggesting exploitation has not yet been reported in the wild. The attack vector depends on user interaction and requires opening a crafted file, meaning the threat is mitigated by careful file handling but still poses a significant risk where users are allowed to open unknown files.

Generated by OpenCVE AI on August 12, 2026 at 12:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Lightroom Classic update that contains the fix for this vulnerability.
  • Ensure that only files from trusted sources are opened; consider disabling automatic file preview for unknown Lightroom files.
  • Run an up‑to‑date antivirus or anti‑malware scan on any Lightroom files before opening them.

Generated by OpenCVE AI on August 12, 2026 at 12:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe lightroom
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:lightroom:*:*:*:*:classic:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe lightroom
Microsoft
Microsoft windows

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe lightroom Classic
Vendors & Products Adobe
Adobe lightroom Classic

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Lightroom Classic | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Lightroom Lightroom Classic
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:00.973Z

Reserved: 2026-05-21T15:28:38.144Z

Link: CVE-2026-48405

cve-icon Vulnrichment

Updated: 2026-08-12T13:36:24.535Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T18:17:29.723

Modified: 2026-08-28T00:17:57.753

Link: CVE-2026-48405

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:50:18Z

Weaknesses