Executive brief
Adobe Lightroom Classic, a professional photo management and editing application, contains a path traversal vulnerability that allows attackers to read arbitrary files from a user's computer. An attacker could craft a malicious file that, when opened by a victim in Lightroom, grants access to sensitive documents and system files outside the intended application directories. This could expose confidential photos, financial records, or other personal data stored on the affected system.
Technical details
The vulnerability is an improper limitation of pathname access (CWE-22: Path Traversal) in Lightroom Classic's file handling logic. The root cause appears to be insufficient validation or normalization of file paths when processing user-supplied or embedded file references, allowing an attacker to use directory traversal sequences (e.g., "../") to escape the intended directory scope. Exploitation requires user interaction—a victim must open a malicious file in Lightroom Classic. Once opened, an attacker can read arbitrary files on the affected system with the privileges of the user running the application. The scope is changed, meaning the impact extends beyond the vulnerable component itself. Adobe has been notified and patches are expected; check Adobe Security Bulletin APSB26-94 for remediation details.
Affected products
- Adobe Lightroom Classic <UNKNOWN>
Timeline
- 2026-08-11: disclosed