Executive brief
Adobe Lightroom Classic contains an authorization flaw that allows an attacker to execute arbitrary code with the privileges of the logged-in user. An attacker could exploit this by crafting a malicious file and tricking a user into opening it, potentially compromising the user's system and access to stored photos and editing data.
Technical details
Lightroom Classic is affected by an incorrect authorization vulnerability (CWE-285) that permits arbitrary code execution in the context of the current user. The vulnerability requires user interaction—specifically opening a malicious file—and depends on conditions beyond the attacker's control. The authorization flaw allows a local attacker to bypass security controls and achieve code execution at the user's privilege level. No public exploit has been reported, but patches are expected to be available through Adobe security updates.
Affected products
- Adobe Lightroom Classic
Timeline
- 2026-08-11: disclosed
- 2026-08-11: advisory