CyberRota
Back to database

CVE-2026-26210

CRITICAL · CVSS 9.8 EPSS 0.10% Public Exploit

Source: NVD + CISA KEV + EPSS · Published: 2026-04-23 · Last synced: 2026-05-23

CyberRota Analysis

Detaylı analiz gerekiyor.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-26210
Severity
CRITICAL
CVSS
9.8
EPSS
0.10%

Original NVD Description

KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deserializes incoming messages using pickle.loads() without validation. Attackers can send a crafted pickle payload to the exposed ZMQ socket to execute arbitrary code on the server with the privileges of the ktransformers process.