Junglewise Threat Intelligence

CVE-2026-48409: Adobe Lightroom Classic out-of-bounds write in file parser

CVE-2026-48409 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Windows, Adobe Lightroom Classic, Adobe Lightroom. Vendors: Microsoft, Adobe.

Executive brief

Adobe Lightroom Classic is a photo management and editing tool used by photographers to organize and process digital images. A vulnerability in how the application parses certain file types could allow an attacker to execute malicious code on a user's computer if they open a specially crafted file, potentially compromising the system and accessing sensitive photo libraries and personal data.

Technical details

Lightroom Classic is affected by an out-of-bounds write vulnerability in its file parsing logic. The vulnerability occurs when the application processes a malicious file without properly validating buffer boundaries, allowing an attacker to write arbitrary data beyond the intended memory region. Exploitation requires user interaction—a victim must open a malicious file—and results in arbitrary code execution in the context of the current user. No remote attack vector is available; the attacker must socially engineer the victim to open the file. Patches are available through Adobe's security updates.

Affected products

  • Adobe Lightroom Classic <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References

Related threats