Junglewise Threat Intelligence

CVE-2026-48410: Adobe Lightroom Classic out-of-bounds write

CVE-2026-48410 · Severity: high · CVSS 7.8 · Published 2026-08-11

Technologies: Microsoft Windows, Adobe Lightroom, Adobe Lightroom Classic. Vendors: Microsoft, Adobe.

Executive brief

Adobe Lightroom Classic, a professional photo editing and management application, is vulnerable to an out-of-bounds write flaw. An attacker can exploit this vulnerability by crafting a malicious file that, when opened by a user in Lightroom Classic, executes arbitrary code with the privileges of the currently logged-in user. This could allow an attacker to steal photos, access sensitive image metadata, or use the compromised system as a foothold for further attacks.

Technical details

Lightroom Classic is affected by an out-of-bounds write vulnerability that permits arbitrary code execution in the context of the current user. The vulnerability is triggered by opening a specially crafted malicious file within the application. An attacker must convince a victim to open the malicious file (user interaction required); network or local file access is not sufficient for exploitation. The out-of-bounds write allows memory corruption that can be leveraged to achieve code execution. Adobe has released patches to address this issue.

Affected products

  • Adobe Lightroom Classic

Timeline

  • 2026-08-11: disclosed

References

Related threats