Executive brief
Adobe Lightroom Classic, a professional photo editing and management application, is vulnerable to arbitrary code execution through deserialization of untrusted data. An attacker can exploit this by crafting a malicious file that, when opened by a user, executes arbitrary code with the permissions of the logged-in user. This could allow attackers to modify or steal photos, access sensitive data, or compromise the user's computer.
Technical details
Lightroom Classic contains a deserialization of untrusted data vulnerability (CWE-502) that allows arbitrary code execution in the context of the current user. The vulnerability is triggered when a victim opens a specially crafted malicious file, requiring user interaction as a precondition. An attacker can exploit this to execute arbitrary code with the same privileges as the affected user. The CVSS 3.1 score of 8.6 reflects the high impact but limited attack vector (user interaction required). Patch information is referenced via Adobe security bulletin APSB26-94, though the advisory details are not currently accessible.
Affected products
- Adobe Lightroom Classic <UNKNOWN>
Timeline
- 2026-08-11: disclosed