OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-103395

CRITICAL · CVSS 9.8 EPSS 0.62% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

LightLLM versions up to 1.2.0 are vulnerable due to an unauthenticated RPyC service that allows remote code execution through deserialization of attacker-supplied arguments. This vulnerability can be exploited to execute arbitrary code with service account privileges, posing a critical risk to any deployment using this software. Organizations utilizing LightLLM should prioritize immediate remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103395
Severity
CRITICAL
CVSS
9.8
EPSS
0.62%

Original NVD Description

LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the visual RPyC port and pass objects with __reduce__ methods to execute arbitrary code with service account privileges.