Junglewise Threat Intelligence

CVE-2026-47940: Adobe Lightroom Classic integer overflow in file handling

CVE-2026-47940 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Adobe Lightroom Classic, Microsoft Windows, Adobe Lightroom. Vendors: Adobe, Microsoft.

Executive brief

Adobe Lightroom Classic contains an integer overflow vulnerability in its file parsing logic that could allow an attacker to execute arbitrary code with the privileges of the user running the application. An attacker would need to trick a user into opening a specially crafted malicious file, making this a moderate threat to photographers and creative professionals who rely on Lightroom for their workflows.

Technical details

The vulnerability is an integer overflow or wraparound condition in Lightroom Classic's file handling code. When processing a malicious file containing crafted data, an integer calculation overflows, leading to a memory corruption condition that can be exploited to achieve arbitrary code execution in the context of the current user. The attack requires user interaction—a victim must explicitly open the malicious file. The vulnerability affects Lightroom Classic, and patches should be available through Adobe's standard security update process (APSB26-94).

Affected products

  • Adobe Lightroom Classic

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: advisory: APSB26-94

References

Related threats