AdobeCVE-2026-48447
Adobe Lightroom Classic: improper authorization
High7.7CVE-2026-48447 · Published Aug 11, 2026 · updated Aug 28, 2026
Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Lightroom Classic Product | <= 15.4.1 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-863
More Adobe advisories
All Adobe| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | Adobe Campaign Classic: improper authorization | Critical10.0 | No fix yet |
| Aug 11 | Adobe Commerce: improper authorization | Critical9.1 | No fix yet |
| Aug 11 | Adobe Lightroom Classic: path traversal | High8.6 | No fix yet |
| Aug 11 | Adobe Commerce: cross-site scripting | High8.7 | No fix yet |
| Aug 11 | Adobe Commerce: cross-site scripting | High7.7 | No fix yet |
| Aug 11 | Adobe Commerce: improper authorization | High7.6 | No fix yet |