Out-of-Bounds Write Vulnerability in Adobe Lightroom Classic
CVE-2026-48406

7.8HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
11 August 2026

What is CVE-2026-48406?

Adobe Lightroom Classic is prone to an out-of-bounds write vulnerability that allows for potential arbitrary code execution within the context of the currently logged-in user. This vulnerability necessitates user interaction, meaning that an attacker must coax a victim into opening a specially crafted file. When successfully exploited, this flaw could lead to unauthorized access and control over the affected system, underscoring the importance of user vigilance and adherence to security best practices.

Affected Version(s)

Lightroom Classic 0 <= 15.4, 15.4.1, 15.3, 15.3.1, 15.2, 15.2.1

Lightroom Classic 0 <= 15.4, 15.4.1, 15.3, 15.3.1, 15.2, 15.2.1

Lightroom Classic 15.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.