{"id":"CVE-2026-103270","title":"LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks","summary":"LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weight…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-306"],"vendor":"ModelTC","product":"LightLLM","affected":["LightLLM <= 1.2.0"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T16:17:08.847","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103270","references":[{"url":"https://github.com/ModelTC/LightLLM","label":"disclosure@vulncheck.com"},{"url":"https://github.com/ModelTC/LightLLM/issues/1609","label":"disclosure@vulncheck.com"},{"url":"https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/api_http.py#L505-L507","label":"disclosure@vulncheck.com"},{"url":"https://github.com/ModelTC/lightllm/blob/v1.2.0/lightllm/server/api_http_rl.py#L51-L139","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/lightllm-through-1.2.0-missing-authentication-on-rl-control-routes","label":"disclosure@vulncheck.com"},{"url":"https://github.com/ModelTC/LightLLM/issues/1609","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-30T15:58:00.673012Z"},"ingestedAt":"2026-09-30T15:07:05.378Z","slug":"CVE-2026-103270","body":"## Overview\n\nLightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group to disrupt inference operations and wedge workers on deployments started with --enable_rl.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":213796,"id":"CVE-2026-103270","ts":1790788579292,"field":"exploit_available","old":"false","new":"true"}]}