Authentication Bypass in LightLLM HTTP API for Reinforcement Learning Control
CVE-2026-103270
8.7HIGH
What is CVE-2026-103270?
LightLLM versions up to 1.2.0 allow unauthenticated access to its HTTP API, specifically through endpoints related to reinforcement learning control. Attackers can exploit this vulnerability to invoke sensitive actions like pausing generation, aborting requests, flushing caches, and updating weights without proper authentication. This can result in the disruption of inference operations and may leave deployments vulnerable to further attacks, particularly for those initiated with the --enable_rl option.
Affected Version(s)
LightLLM 0 <= 1.2.0
