CVE-2026-28707: Medium severity LLM-on-Ray vulnerability
Protection mechanism failure for some LLM-on-Ray before version 1.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28707?
CVE-2026-28707 has a risk severity rating of 51.
How do I fix CVE-2026-28707?
To remediate CVE-2026-28707, update to LLM-on-Ray version 1.0 or later.
What type of vulnerability is CVE-2026-28707?
CVE-2026-28707 is classified as a protection mechanism failure that may lead to privilege escalation.
Who is affected by CVE-2026-28707?
Users of LLM-on-Ray versions prior to 1.0 may be affected by CVE-2026-28707.
Can CVE-2026-28707 be exploited easily?
CVE-2026-28707 may be exploitable by an unprivileged adversary using a low complexity attack.