CVE-2026-103041

LOWCVSS 9.3 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code with service privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-09-30: 309-30
Referenced assets3 URLs
Full discourse3 posts
  • Security Arsenal, LLC@SecurityAr58409

    🔒 #CyberSecurity CVE-2026-102911, CVE-2026-103040, CVE-2026-103041: Critical LLM Infrastructure … "In the last 72 hours, NVD published three critical, network-vector vulnerabilities…" 🔗 https://securityarsenal.com/blog/cve-2026-102911-cve-2026-103040-cve-2026-103041-critical-llm-infrastructure-rce-detection-and-remediation-guide #CyberSecurity #ThreatIntel #cve2026102911 #critical #cve

    0000023
    35 followersView on X
  • ThreatAft@ThreatAft

    🔐🚨 LIGHTLLM — 3 CVEs, 2 × CVSS 9.8 • CVE-2026-103040 — 9.8 — Router profiler RCE • CVE-2026-103041 — 9.8 — Multimodal embed cache RCE • CVE-2026-103042 — 7.5 — NCCL memory exhaustion 🔗 https://threataft.com/articles/lightllm-mass-disclosure-cve-2026-103040-103041-103042?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #ThreatIntel #LightLLM #AI #CVE #RCE #PatchNow

    0000059
    44 followersView on X
  • Security Arsenal, LLC@SecurityAr58409

    🔒 #CyberSecurity CVE-2026-103041: LightLLM Unauthenticated RPyC Pickle Deserialization RCE — Det… "NVD has published CVE-2026-103041, a CVSS 9.8 CRITICAL vulnerability affecting LightLLM…" 🔗 https://securityarsenal.com/blog/cve-2026-103041-lightllm-unauthenticated-rpyc-pickle-deserialization-rce-detection-and-remediation-guide #CyberSecurity #ThreatIntel #cve2026103041 #critical #cve

    0000031
    35 followersView on X

Explore more