Multiple vulnerabilities in LightLLM through version 1.2.0 expose reachable AI inference deployments to unauthenticated remote code execution (RCE) and operational disruption. Critical flaws tracked as CVE-2026-103040, CVE-2026-103041, and CVE-2026-103395 involve unsafe pickle-backed deserialization in exposed RPyC services, including profiling and visual_only image-inference deployments. An attacker able to reach an affected RPyC port can submit crafted Python objects—such as one abusing __reduce__—and execute code with the privileges of the LightLLM service account. The profiling path requires --enable_profiling; the visual deployment issue affects the remote_infer_images method.
Additional weaknesses permit unauthenticated denial-of-service and inference disruption. CVE-2026-103042 can exhaust memory through the NCCL control channel, while CVE-2026-103270 exposes reinforcement-learning control endpoints when LightLLM runs with --enable_rl, allowing remote callers to pause generation, abort requests, flush caches, initialize weight-update groups, and potentially wedge workers. No public exploitation, known victims, or CISA KEV listing had been reported. Organizations should disable profiling, RPyC, and RL features where unnecessary; restrict all related service and dynamically assigned profiler ports to trusted networks; apply vendor fixes when available; review potentially exposed instances; and rotate credentials accessible to inference processes.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-103395 was published for LightLLM through 1.2.0 in visual_only deployments. The unauthenticated visual RPyC service accepts pickle-deserialized attacker-controlled arguments to remote_infer_images, allowing arbitrary code execution as the LightLLM service account.
CVE-2026-103270 was published for LightLLM through 1.2.0, where deployments launched with --enable_rl expose reinforcement-learning control endpoints without authentication. Remote attackers could invoke endpoints including pause_generation, abort_request, flush_cache, and init_weights_update_group to disrupt inference and potentially wedge workers.
Three vulnerabilities affecting LightLLM through version 1.2.0 were disclosed: CVE-2026-103040 and CVE-2026-103041, unauthenticated RCE flaws involving pickle deserialization in RPyC services, and CVE-2026-103042, an unauthenticated NCCL control-channel memory-exhaustion flaw. At disclosure, no confirmed patch or public exploitation had been reported.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
linuxsecurity.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcethreataft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.