OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-103270

HIGH · CVSS 7.5 EPSS 0.51% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

LightLLM versions up to 1.2.0 are vulnerable due to the lack of authentication checks on their public HTTP API, allowing unauthenticated attackers to access critical endpoints such as /pause_generation and /abort_request. This vulnerability can lead to disruption of inference operations and potential denial of service by wedging workers in deployments configured with reinforcement learning. Organizations using this software should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103270
Severity
HIGH
CVSS
7.5
EPSS
0.51%

Original NVD Description

LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group to disrupt inference operations and wedge workers on deployments started with --enable_rl.