CVE-2026-103270: LightLLM through 1.2.0 Missing Authentication on RL Control Routes
LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pausegeneration, /abortrequest, /flushcache, and /initweightsupdategroup to disrupt inference operations and wedge workers on deployments started with --enablerl.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments of LightLLM through 1.2.0 are exposed when started with --enable_rl and the HTTP API is reachable by untrusted clients. The affected reinforcement-learning control routes are mounted on the public HTTP API.
What does an attacker need to exploit this issue?
An attacker only needs network access to the exposed HTTP API. No authentication, privileges, or user interaction are required.
What operational impact should responders expect?
An unauthenticated caller can invoke control endpoints including /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group. These calls can disrupt inference operations and wedge workers.
How can I determine whether an instance is affected?
Check whether the deployment is running LightLLM version 1.2.0 or earlier and was started with --enable_rl. Also verify whether untrusted networks can reach its public HTTP API.