Junglewise Threat Intelligence

CVE-2026-48404: Adobe Lightroom Classic out-of-bounds write vulnerability

CVE-2026-48404 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Windows, Adobe Lightroom, Adobe Lightroom Classic. Vendors: Microsoft, Adobe.

Executive brief

Adobe Lightroom Classic contains an out-of-bounds write flaw that allows attackers to execute arbitrary code with the privileges of the user running the application. An attacker must trick a user into opening a specially crafted malicious file to trigger the vulnerability, potentially compromising the victim's system and access to stored photos and data.

Technical details

The vulnerability is an out-of-bounds write in Adobe Lightroom Classic that arises from improper input validation or buffer handling, likely during file parsing or processing. Exploitation requires user interaction—specifically, the victim must open a malicious file crafted to trigger the out-of-bounds write condition. A successful exploit results in arbitrary code execution in the context of the current user. The vulnerability has been assigned CVE-2026-48404 with a CVSS score of 7.8 (high severity), and no active exploitation in the wild has been reported as of the advisory date.

Affected products

  • Adobe Lightroom Classic

Timeline

  • 2026-08-11: disclosed

References

Related threats