Skip to content
AdobeCVE-2026-48447

Adobe Lightroom Classic: improper authorization

High7.7CVE-2026-48447 · Published Aug 11, 2026 · updated Aug 28, 2026

Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Adobe advisory

Affected versions

PackageAffectedFixed in
Lightroom Classic
Product
<= 15.4.1No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-863

More Adobe advisories

All Adobe
Advisory
Adobe Campaign Classic: improper authorization
Critical10.0Aug 11
Adobe Commerce: improper authorization
Critical9.1Aug 11
Adobe Lightroom Classic: path traversal
High8.6Aug 11
Adobe Commerce: cross-site scripting
High8.7Aug 11
Adobe Commerce: cross-site scripting
High7.7Aug 11
Adobe Commerce: improper authorization
High7.6Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.