CVE-2026-48409 – Adobe Lightroom Classic

CVSS 7.8 IMPORTANT High with EoP or RCE – Expedited Deployment

“Malicious files can turn routine image workflows into a path for code execution or sensitive data exposure.”

Adobe Lightroom Classic is affected by ten high-severity vulnerabilities involving unsafe deserialization, path traversal, integer overflow, and out-of-bounds writes. CVE-2026-48397 and CVE-2026-48441 each have a CVSS score of 8.6, High severity. CVE-2026-47940, CVE-2026-48404, CVE-2026-48405, CVE-2026-48406, CVE-2026-48407, CVE-2026-48408, CVE-2026-48409, and CVE-2026-48410 each have a CVSS score of 7.8, High severity.

Most of these vulnerabilities can result in arbitrary code execution in the context of the current user. The path traversal vulnerability can expose sensitive files and directories outside the intended access scope. Exploitation requires a victim to open a malicious file.

Key Details

Affected Product
Adobe Lightroom
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-787
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.