Description
Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Lightroom Classic contains an out‑of‑bounds write flaw that, when triggered by opening a specially crafted file, can overwrite memory beyond the intended bounds and lead to arbitrary code execution. The flaw allows the attacker to execute code with the privileges of the user who opens the file, potentially compromising confidential data, installing malware, or taking full control of the affected system. The weakness is identified as CWE‑787.

Affected Systems

Adobe Lightroom Classic on any installation where the vulnerability has not been patched. No specific version information is listed in the CNA data, so all releases that include the vulnerable component are considered at risk.

Risk and Exploitability

The CVSS score of 7.8 indicates moderate to high severity. The EPSS score is not reported, and the vulnerability is not listed in CISA KEV. Exploitation requires user interaction; a victim must open a malicious file. The likely attack vector is a social engineering scenario where the attacker sends a file that a user opens or where a user downloads an infected file. Given the lack of automated exploitation and the need for user action, the immediate threat is lower than high‑risk remotely exploitable bugs, but the impact remains significant if an employee opens a malicious file.

Generated by OpenCVE AI on August 12, 2026 at 12:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Adobe’s security advisories and install the latest Lightroom Classic update that contains the fix for the out‑of‑bounds write flaw.
  • Enable or enforce a file‑open confirmation prompt to require explicit user approval before any unknown or potentially malicious file is processed by Lightroom.
  • Apply standard application‑control or endpoint protection rules that restrict the execution of unknown binaries and monitor for unusual memory writes within the Lightroom process.

Generated by OpenCVE AI on August 12, 2026 at 12:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe lightroom
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:lightroom:*:*:*:*:classic:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe lightroom
Microsoft
Microsoft windows

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe lightroom Classic
Vendors & Products Adobe
Adobe lightroom Classic

Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Lightroom Classic | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Lightroom Lightroom Classic
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:03.098Z

Reserved: 2026-05-21T15:28:38.144Z

Link: CVE-2026-48409

cve-icon Vulnrichment

Updated: 2026-08-11T20:00:58.142Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T18:17:30.470

Modified: 2026-08-28T00:17:58.223

Link: CVE-2026-48409

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:49:51Z

Weaknesses