Junglewise Threat Intelligence

CVE-2026-21349: Adobe Lightroom Desktop out-of-bounds write

CVE-2026-21349 · Severity: high · CVSS 7.8 · Published 2026-02-10

Vendors: Adobe.

Executive brief

Adobe Lightroom Desktop is a professional photo editing and management application used by photographers and designers. A flaw in the application allows attackers to execute arbitrary code with the privileges of the logged-in user if a victim opens a malicious image or project file, potentially leading to data theft, system compromise, or malware installation.

Technical details

The vulnerability is an out-of-bounds write flaw in Adobe Lightroom Desktop that enables arbitrary code execution. The attack requires user interaction—specifically, a victim must open a specially crafted malicious file (image or project file). The vulnerability affects Lightroom Desktop version 15.1 and earlier. An out-of-bounds write allows an attacker to corrupt memory and overwrite critical data structures, including function pointers or return addresses, to redirect execution to attacker-controlled code. Adobe has released patches to address this issue.

Affected products

  • Adobe Lightroom Desktop 15.1 and earlier

Timeline

  • 2026-02-10: disclosed

References