Authentication Bypass in LightLLM HTTP API for Reinforcement Learning Control
CVE-2026-103270

8.7HIGH

Key Information:

Vendor

Modeltc

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-103270?

LightLLM versions up to 1.2.0 allow unauthenticated access to its HTTP API, specifically through endpoints related to reinforcement learning control. Attackers can exploit this vulnerability to invoke sensitive actions like pausing generation, aborting requests, flushing caches, and updating weights without proper authentication. This can result in the disruption of inference operations and may leave deployments vulnerable to further attacks, particularly for those initiated with the --enable_rl option.

Affected Version(s)

LightLLM 0 <= 1.2.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mingkai Yu
Jiajia Liu
.