Description
Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Lightroom Classic is vulnerable to an out‑of‑bounds write that can be triggered by malicious input files. The flaw can be exploited to execute arbitrary code with the privileges of the user who opens the file, potentially compromising system or application integrity and allowing further lateral movement.

Affected Systems

Adobe Lightroom Classic instances are affected. No specific version ranges are provided, so any deployment using a pre‑patch copy may be vulnerable.

Risk and Exploitability

The CVSS score of 7.8 classifies the vulnerability as high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Exploitation requires the victim to open a malicious file, indicating that user interaction is necessary for successful attack. The risk is therefore moderate to high for environments where users routinely open unknown or unverified photos or catalogs.

Generated by OpenCVE AI on August 12, 2026 at 12:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Lightroom Classic security update that includes AP‑26‑94 to patch the out‑of‑bounds write flaw.
  • Configure Lightroom to disable automatic opening of files or enforce a manual approval step before processing input files.
  • Educate users to avoid opening photos or catalogs from untrusted sources and to verify file integrity before opening them.

Generated by OpenCVE AI on August 12, 2026 at 12:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe lightroom
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:lightroom:*:*:*:*:classic:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe lightroom
Microsoft
Microsoft windows

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe lightroom Classic
Vendors & Products Adobe
Adobe lightroom Classic

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Lightroom Classic | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Lightroom Lightroom Classic
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:33:55.850Z

Reserved: 2026-05-21T15:28:38.144Z

Link: CVE-2026-48406

cve-icon Vulnrichment

Updated: 2026-08-12T13:36:19.447Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T18:17:29.880

Modified: 2026-08-28T00:17:57.873

Link: CVE-2026-48406

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:49:55Z

Weaknesses