Deserialization Vulnerability in Intel Extension for PyTorch Software
CVE-2026-35502

4.6MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
11 August 2026

What is CVE-2026-35502?

A deserialization flaw exists in earlier versions of Intel Extension for PyTorch, allowing unprivileged adversaries to exploit this weakness to escalate privileges. This vulnerability requires local access to the system and involves an unauthenticated user. While the risk is contingent upon the attacker's knowledge and user interaction, its potential consequences could impact the confidentiality, integrity, and availability of the affected systems at a minimal level. Users and administrators should stay informed and apply necessary patches to safeguard against this vulnerability.

Affected Version(s)

Intel(R) Extension for PyTorch before version 2.8.0

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.