Deserialization Vulnerability in Adobe Lightroom Classic
CVE-2026-48397
8.6HIGH
What is CVE-2026-48397?
Adobe Lightroom Classic has a vulnerability that allows for the deserialization of untrusted data, potentially leading to arbitrary code execution within the context of the current user. An attacker must trick a victim into opening a specially crafted file to exploit this vulnerability, making user awareness and safe file handling essential in mitigating risks.
Affected Version(s)
Lightroom Classic 0 <= 15.4, 15.4.1, 15.3, 15.3.1, 15.2, 15.2.1
Lightroom Classic 0 <= 15.4, 15.4.1, 15.3, 15.3.1, 15.2, 15.2.1
Lightroom Classic 15.5