Junglewise Threat Intelligence

CVE-2026-48447: Adobe Lightroom Classic arbitrary code execution via incorrect authorization

CVE-2026-48447 · Severity: high · CVSS 7.7 · Published 2026-08-11

Technologies: Microsoft Windows, Adobe Lightroom Classic, Adobe Lightroom. Vendors: Microsoft, Adobe.

Executive brief

Adobe Lightroom Classic contains an authorization flaw that allows an attacker to execute arbitrary code with the privileges of the logged-in user. An attacker could exploit this by crafting a malicious file and tricking a user into opening it, potentially compromising the user's system and access to stored photos and editing data.

Technical details

Lightroom Classic is affected by an incorrect authorization vulnerability (CWE-285) that permits arbitrary code execution in the context of the current user. The vulnerability requires user interaction—specifically opening a malicious file—and depends on conditions beyond the attacker's control. The authorization flaw allows a local attacker to bypass security controls and achieve code execution at the user's privilege level. No public exploit has been reported, but patches are expected to be available through Adobe security updates.

Affected products

  • Adobe Lightroom Classic

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: advisory

References

Related threats