Credential Harvesting Vulnerability in PyTorch Lightning by Lightning AI
CVE-2026-44484

9.3CRITICAL

Key Information:

Vendor
CVE Published:
14 May 2026

What is CVE-2026-44484?

PyTorch Lightning, a deep learning framework designed for pretraining and finetuning AI models, has a vulnerability that could allow malicious actors to exploit functionalities resembling a credential harvesting mechanism. This caveat was introduced in versions 2.6.2 and may expose user credentials to unauthorized access. Developers utilizing this framework should review the security advisory and take necessary precautions to safeguard sensitive information.

Affected Version(s)

pytorch-lightning 2.6.2

pytorch-lightning 2.6.3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.