Description
Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-08-11
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Lightroom Classic contains an improper limitation of a pathname to a restricted directory (Path Traversal) that permits an attacker to request arbitrary files from the file system. The flaw allows a victim to open a malicious file that references a pathname outside the designated directory, resulting in the read of sensitive files. Because the file must be opened by a user, the attack requires user interaction, and the vulnerability changes the scope of the application’s access rights.

Affected Systems

The vulnerability affects Adobe Lightroom Classic. No specific product versions are listed in the official advisory, so all installations of the software are potentially impacted until a patch is applied.

Risk and Exploitability

The CVSS score of 8.6 classifies it as a high severity flaw, though the EPSS score is unavailable, implying limited data on exploitation likelihood. It is not currently listed in CISA’s KEV catalog. Given that exploitation requires a user to open a crafted file, the risk is moderate in environments where users lack access to sensitive directories, but any exposure to untrusted files elevates the threat. Patch or updated version releases from Adobe are the primary mitigation, with additional controls recommended where immediate updates are not possible.

Generated by OpenCVE AI on August 12, 2026 at 13:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Adobe Lightroom Classic to the latest version that includes the path‑traversal fix.
  • Apply the principle of least privilege so that users running Lightroom have read access only to directories they legitimately need to use.
  • Restrict the ability to open or execute arbitrary files in Lightroom, for example by disabling automatic opening of files from untrusted locations or integrating file type validation checks.

Generated by OpenCVE AI on August 12, 2026 at 13:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe lightroom
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:lightroom:*:*:*:*:classic:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe lightroom
Microsoft
Microsoft windows

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe lightroom Classic
Vendors & Products Adobe
Adobe lightroom Classic

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Lightroom Classic | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Lightroom Lightroom Classic
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:11.318Z

Reserved: 2026-05-21T15:28:38.146Z

Link: CVE-2026-48441

cve-icon Vulnrichment

Updated: 2026-08-11T18:57:43.704Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T18:17:32.457

Modified: 2026-08-28T00:18:02.037

Link: CVE-2026-48441

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:49:52Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')