CVE-2026-47940
published 2026-08-11CVE-2026-47940: Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current…
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.18%
7.7th percentile
Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | lightroom | < 15.5 | 15.5 |
| adobe | lightroom_classic | <= 15.4, 15.4.1, 15.3, 15.3.1, 15.2, 15.2.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Adobe Lightroom Classic up to 15.4.1 integer overflow (Nessus ID 339065 / WID-SEC-2026-2773)
vuldb·2026-08-24·CVSS 7.8
CVE-2026-47940 [HIGH] Adobe Lightroom Classic up to 15.4.1 integer overflow (Nessus ID 339065 / WID-SEC-2026-2773)
A vulnerability identified as problematic has been detected in Adobe Lightroom Classic up to 15.4.1. This vulnerability affects unknown code. This manipulation causes integer overflow.
The identification of this vulnerability is CVE-2026-47940. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
GHSA
Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user.
ghsa_unreviewed·2026-08-11
CVE-2026-47940 [HIGH] CWE-190 Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user.
Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-11
Published