Path Traversal Vulnerability in Adobe Lightroom Classic
CVE-2026-48441

8.6HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
11 August 2026

What is CVE-2026-48441?

Adobe Lightroom Classic contains a vulnerability that allows for the improper limitation of a pathname to a restricted directory, resulting in a potential path traversal issue. An attacker can exploit this vulnerability, granted that the victim opens a specially crafted malicious file, leading to unauthorized access to sensitive files and directories outside the intended access scope. Users must be aware of this risk to mitigate potential exploitation.

Affected Version(s)

Lightroom Classic 0 <= 15.4, 15.4.1, 15.3, 15.3.1, 15.2, 15.2.1

Lightroom Classic 0 <= 15.4, 15.4.1, 15.3, 15.3.1, 15.2, 15.2.1

Lightroom Classic 15.5

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.