Unauthenticated Vulnerability in Angel Product by Tencent
CVE-2026-92785

9.2CRITICAL

Key Information:

Vendor

Angel-ml

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92785?

The Angel product up to version 3.3.0 exposes a vulnerability due to the deserialization of untrusted payloads using Kryo without proper class registration and allowlist validation. This flaw allows unauthenticated attackers over the network to create instances of arbitrary classes or potentially exhaust memory on the coordinator by sending specially crafted serialized objects to the master RPC endpoint, leading to potential service disruption and unauthorized access.

Affected Version(s)

angel 0 <= 3.3.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.