Description
Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Lightroom Classic contains an out‑of‑bounds write flaw that allows an attacker to execute arbitrary code with the privileges of the user who opens a crafted file. The weakness is a classic buffer overflow (CWE‑787) exposed when parsing maliciously formed data inside a Lightroom image or catalog file. If exploited, any code the attacker injects would run with the victim’s account rights, potentially giving full control over the system for that user. The vulnerability is not a denial‑of‑service flaw, but a full code‑execution risk that can lead to data compromise or further lateral movement.

Affected Systems

The affected product is Adobe Lightroom Classic, as listed by the vendor and CNA. All builds of Lightroom Classic prior to the release that contains the out‑of‑bounds write fix are vulnerable. Specific version information is not disclosed in this advisory, so administrators should refer to Adobe’s security bulletin for the precise patch version. Currently, only the Adobe product is listed; no other third‑party software is impacted.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. Exploitation requires user interaction – the victim must open a malicious file – meaning the attack vector is user‑initiated with a local attack model. Because the EPSS score is not available, a precise probability of exploitation cannot be derived, but the lack of a public KEV listing suggests no known widespread attacks yet. Nonetheless, the combination of high impact and the ease of triggering by opening a file makes it a serious risk for environments where users ingest untrusted media.

Generated by OpenCVE AI on August 12, 2026 at 12:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Adobe’s latest Lightroom Classic security patch that addresses the out‑of‑bounds write flaw
  • Configure Lightroom Classic to run in a restricted or sandboxed environment and do not enable automatic opening of unknown files
  • Train users to avoid opening suspicious image or catalog files, and use standard email scanning or content inspection before opening

Generated by OpenCVE AI on August 12, 2026 at 12:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe lightroom
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:lightroom:*:*:*:*:classic:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe lightroom
Microsoft
Microsoft windows

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe lightroom Classic
Vendors & Products Adobe
Adobe lightroom Classic

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Lightroom Classic | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Lightroom Lightroom Classic
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:11.672Z

Reserved: 2026-05-21T15:28:38.144Z

Link: CVE-2026-48407

cve-icon Vulnrichment

Updated: 2026-08-11T18:58:30.200Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T18:17:30.107

Modified: 2026-08-28T00:17:57.990

Link: CVE-2026-48407

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:50:23Z

Weaknesses