Escalation of Privilege Vulnerability in LLM-on-Ray Software by Intel
CVE-2026-28707

5.4MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
11 August 2026

What is CVE-2026-28707?

The LLM-on-Ray software prior to version 1.0 has a vulnerability that may allow an adversary with unprivileged access to escalate privileges under certain conditions. This occurs in user applications within Ring 3, where an attacker can exploit the protection mechanism failure through local access without requiring advanced internal knowledge. A low complexity attack coupled with passive user interaction can lead to potential impacts on the system's confidentiality, integrity, and availability.

Affected Version(s)

LLM-on-Ray before version 1.0

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.