Out-of-Bounds Write Vulnerability in Adobe Lightroom Classic
CVE-2026-48405

7.8HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
11 August 2026

What is CVE-2026-48405?

Adobe Lightroom Classic contains a vulnerability that allows for out-of-bounds write operations, potentially leading to arbitrary code execution in the context of an authenticated user. This security concern arises when a user interacts with a maliciously crafted file, thereby enabling an attacker to execute arbitrary code. It is essential for users to be cautious and only open files from trusted sources to mitigate the risk of exploitation. For further details, refer to Adobe's official security advisory.

Affected Version(s)

Lightroom Classic 0 <= 15.4, 15.4.1, 15.3, 15.3.1, 15.2, 15.2.1

Lightroom Classic 0 <= 15.4, 15.4.1, 15.3, 15.3.1, 15.2, 15.2.1

Lightroom Classic 15.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.