Description
Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: 2026-08-11
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Incorrect Authorization flaw identified as CWE‑863 that allows an attacker to execute arbitrary code in the context of the user running Lightroom Classic. The flaw alters the privilege scope, enabling unauthorized actions when a malicious file is processed. The impact is that the code runs with the victim’s user rights, which could lead to system compromise or data leakage.

Affected Systems

Adobe Lightroom Classic is affected. No specific version range is disclosed in the announcement, so all installations of Lightroom Classic are potentially vulnerable until a patch is released.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity issue, though the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the victim to open a crafted file, and the description notes that additional conditions beyond the attacker’s control are necessary, suggesting that the practical exploitation window may be limited. Nevertheless, the scope change raises the risk, especially in environments where users commonly open unknown files. Monitoring and prompt patching are therefore advised.

Generated by OpenCVE AI on August 12, 2026 at 13:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and install the Adobe security update for Lightroom Classic as soon as it is released.
  • Configure the operating system or file‑system to prevent users from opening untrusted files in Lightroom, such as by using a sandbox or disabling the “Open File” menu for unknown file types.
  • Educate users to avoid opening files from untrusted or unfamiliar sources and ensure an up‑to‑date antivirus solution scans files before they are opened.

Generated by OpenCVE AI on August 12, 2026 at 13:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe lightroom
Microsoft
Microsoft windows
CPEs cpe:2.3:a:adobe:lightroom:*:*:*:*:classic:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Adobe lightroom
Microsoft
Microsoft windows

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe lightroom Classic
Vendors & Products Adobe
Adobe lightroom Classic

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Title Lightroom Classic | Incorrect Authorization (CWE-863)
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Adobe Lightroom Lightroom Classic
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:17.827Z

Reserved: 2026-05-21T15:28:38.146Z

Link: CVE-2026-48447

cve-icon Vulnrichment

Updated: 2026-08-12T13:36:03.116Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T18:17:33.157

Modified: 2026-08-28T00:18:04.610

Link: CVE-2026-48447

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:49:54Z

Weaknesses