Sceawere

Vulnerability Detail

CVE-2026-48447UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Lightroom Classic Incorrect Authorization Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.7
Creation Date
6h ago
Vendor
Adobe
Product
Lightroom Classic
Attack Type
Incorrect Authorization (CWE-863)
Vector String
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.7",
  "pubDate": "2026-08-11T18:17:33.157Z",
  "pubdate": "2026-08-11T18:17:33.157Z",
  "executiveSummary": "Adobe Lightroom Classic is affected by an Incorrect Authorization vulnerability that introduces significant security risks to end users. The primary impact of this flaw is arbitrary code execution, enabling an adversary to execute arbitrary code within the security context of the currently logged-in user. This vulnerability affects the Lightroom Classic product suite, potentially compromising the integrity, confidentiality, and availability of the host system depending on user privileges.\nThe risk implications are elevated due to the potential for full code execution, which could allow malicious actors to perform unauthorized operations, access sensitive data, or install further malware. Successful exploitation requires specific conditions and active victim participation. Specifically, exploitation is contingent upon user interaction, requiring the target victim to manually open a crafted, malicious file processed by the application. Furthermore, the overall exploit mechanism relies on preconditions and triggers that reside beyond the direct control of the attacker.\nBecause the vulnerability involves a changed scope, the resulting compromise may extend beyond the immediate boundaries of the vulnerable application component to impact broader system resources accessible to the user context. Mitigating this risk requires strict adherence to security best practices regarding file handling and user awareness when interacting with untrusted media.",
  "technicalDetails": "The vulnerability stems from an Incorrect Authorization flaw within Adobe Lightroom Classic, specifically residing in the component responsible for parsing and handling specific file formats. Due to insufficient authorization checks and improper validation logic during the processing of these files, the application mishandles security boundaries when a crafted file is opened.\nThe attack flow requires user interaction as a mandatory prerequisite. An attacker must first deliver a malicious file to the target victim via social engineering, phishing, or other distribution vectors. Once the victim initiates the action of opening the malicious file using Lightroom Classic, the application attempts to process the malformed structure. Due to the authorization flaw, the application fails to adequately verify the permissions or context associated with operations triggered during the file parsing lifecycle.\nThis breakdown in authorization checks allows the malformed file contents to manipulate application execution flows. By weaponizing specific parsing routines within the vulnerable component, an attacker can achieve arbitrary code execution. The malicious payload executes leveraging the privileges of the current user session, meaning the extent of the system compromise is directly tied to the user's access rights. Network exposure and authentication requirements are minimal from a remote standpoint, as the primary vector relies entirely on local file parsing triggered by user action, placing the exploitation vector squarely within the domain of client-side file handling weaknesses. Post-exploitation impact includes the potential execution of unauthorized commands, interactive shell access within the user context, and manipulation of user-accessible files."
}
CVE-2026-48447: Lightroom Classic Incorrect Authorization Vulnerability (HIGH Severity, CVSS: 7.7) - Sceawere