Description
Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Lightroom Classic is affected by an out‑of‑bounds write that allows an attacker to overwrite memory of the process when the user opens a crafted file, which can lead to arbitrary code execution in the context of the current user. The vulnerability is a classic buffer overflow (CWE‑787) that does not require elevated privileges to be abused. Attackers can trigger it only if a victim opens a malicious file, so it is user‑interaction‑dependent.

Affected Systems

Adobe Lightroom Classic. No specific affected version is listed in the CVE data, so all installations that have not applied the latest Adobe update may be vulnerable.

Risk and Exploitability

The CVSS score is 7.8, indicating a high severity. The EPSS score is not available and the vulnerability is not in the CISA KEV catalog, suggesting limited publicly known exploit activity. Because execution requires a malicious file to be opened by a user, the practical risk is significant for users who frequently handle unknown files or trust file sharing without verification.

Generated by OpenCVE AI on August 12, 2026 at 12:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Adobe Lightroom Classic patch or update, which addresses the out‑of‑bounds write flaw.
  • Configure or disable automatic opening of unknown or untrusted file types, and validate file sources before opening.
  • Educate users to avoid opening files from untrusted or anonymous sources, and employ email attachment scanning to detect potential malicious files.

Generated by OpenCVE AI on August 12, 2026 at 12:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe lightroom
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:lightroom:*:*:*:*:classic:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe lightroom
Microsoft
Microsoft windows

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe lightroom Classic
Vendors & Products Adobe
Adobe lightroom Classic

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Lightroom Classic | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Lightroom Lightroom Classic
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:33:58.025Z

Reserved: 2026-05-21T15:28:38.144Z

Link: CVE-2026-48408

cve-icon Vulnrichment

Updated: 2026-08-12T13:36:14.354Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T18:17:30.320

Modified: 2026-08-28T00:17:58.107

Link: CVE-2026-48408

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:49:49Z

Weaknesses