Executive brief
Adobe Lightroom Classic contains an out-of-bounds write flaw that allows attackers to execute arbitrary code with the privileges of the user running the application. An attacker must trick a user into opening a specially crafted malicious file to trigger the vulnerability, potentially compromising the victim's system and access to stored photos and data.
Technical details
The vulnerability is an out-of-bounds write in Adobe Lightroom Classic that arises from improper input validation or buffer handling, likely during file parsing or processing. Exploitation requires user interaction—specifically, the victim must open a malicious file crafted to trigger the out-of-bounds write condition. A successful exploit results in arbitrary code execution in the context of the current user. The vulnerability has been assigned CVE-2026-48404 with a CVSS score of 7.8 (high severity), and no active exploitation in the wild has been reported as of the advisory date.
Affected products
- Adobe Lightroom Classic
Timeline
- 2026-08-11: disclosed