Incorrect Authorization in Adobe Lightroom Classic
CVE-2026-48447

7.7HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
11 August 2026

What is CVE-2026-48447?

Adobe Lightroom Classic is susceptible to an Incorrect Authorization vulnerability that may allow an attacker to execute arbitrary code within the context of the current user. This exploitation necessitates user interaction, as a victim must open a specially crafted malicious file. The exploitability of the issue is contingent on external conditions beyond the attacker's control, effectively changing the original scope.

Affected Version(s)

Lightroom Classic 0 <= 15.4, 15.4.1, 15.3, 15.3.1, 15.2, 15.2.1

Lightroom Classic 0 <= 15.4, 15.4.1, 15.3, 15.3.1, 15.2, 15.2.1

Lightroom Classic 15.5

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.