Description
Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Lightroom Classic is affected by an out‑of‑bounds write flaw that, if triggered, can allow a malicious file to overwrite memory beyond its bounds. This can lead to arbitrary code execution in the context of the user who opens the file, as the vulnerability triggers during file import. The weakness is a classic buffer overflow problem identified as CWE‑787.

Affected Systems

The affected product is Adobe Lightroom Classic. No specific release or version numbers are disclosed in the advisory, so any installation of Lightroom Classic that predates the security update is potentially vulnerable. Users should refer to the Adobe Security Advisory for the list of impacted versions and patch guidance.

Risk and Exploitability

The CVSS score of 7.8 classifies this flaw as High severity. EPSS is not available, but the absence of a publicly known exploit and the requirement of user interaction reduce the immediate likelihood of exploitation. The flaw is not listed in CISA KEV, indicating no confirmed active exploitation as of the last assessment. Nevertheless, because the exploit path involves opening a crafted file, the attack vector is local; a malicious actor would need to provide the user with a specially crafted Lightroom file and convince them to open it.

Generated by OpenCVE AI on August 12, 2026 at 12:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security update for Lightroom Classic released by Adobe, as stated in the official advisory.
  • Pre‑emptively remove or quarantine any untrusted Lightroom files that may have been inadvertently opened to prevent code execution.
  • Train users to avoid opening unknown Lightroom documents and to verify file provenance before opening.

Generated by OpenCVE AI on August 12, 2026 at 12:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe lightroom
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:lightroom:*:*:*:*:classic:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe lightroom
Microsoft
Microsoft windows

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe lightroom Classic
Vendors & Products Adobe
Adobe lightroom Classic

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Title Lightroom Classic | Out-of-bounds Write (CWE-787)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Lightroom Lightroom Classic
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:09.172Z

Reserved: 2026-05-21T15:28:38.144Z

Link: CVE-2026-48410

cve-icon Vulnrichment

Updated: 2026-08-12T13:36:09.067Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T18:17:30.627

Modified: 2026-08-28T00:17:58.330

Link: CVE-2026-48410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:50:28Z

Weaknesses