Escalation of Privilege Vulnerability in Intel oneCCL Bindings for PyTorch
CVE-2026-24693

5.4MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
11 August 2026

What is CVE-2026-24693?

The Intel oneCCL Bindings for PyTorch prior to version v2.8.0 exhibit a protection mechanism failure in Ring 3: User Applications. This vulnerability may be exploited by an unprivileged software adversary alongside a privileged user, potentially leading to an escalation of privilege through a low complexity attack. The attack may necessitate local access and requires minimal user interaction. If exploited, the vulnerability can significantly impact the confidentiality, integrity, and availability of the affected system.

Affected Version(s)

Intel(R) oneCCL Bindings for PyTorch before version v2.8.0

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.