CVE-2026-27482Disclosure(anyscale / ray)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Ray is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but does not cover DELETE, and key DELETE endpoints are unauthenticated by default. If the dashboard/agent is reachable (e.g., --dashboard-host=0.0.0.0), a web page via DNS rebinding or same-network access can issue DELETE requests that shut down Serve or delete jobs without user interaction. This is a drive-by availability impact. The fix for this vulnerability is to update to Ray 2.54.0 or higher.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-396

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ray

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ray

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-10: 1Technical Details · 2026-03-10: 103-10
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Mukund | Muks@CyberAmyntas
    Disclosure

    Ray Dashboard has a medium-severity auth bypass (CVE-2026-27482) that lets unauthenticated attackers delete running jobs and shut down Serve apps on Ray 2.53.0 and below if the dashboard is exposed https://www.raxe.ai/labs/advisories/RAXE-2026-026 @RaxeAi

    Post summary

    The advisory reports CVE-2026-27482, an authentication bypass in Ray Dashboard that lets unauthenticated attackers delete jobs and terminate Serve apps on Ray 2.53.0 and earlier when the dashboard is exposed. No patch, PoC, or evidence of active exploitation is mentioned.

    0000075
    1.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanyscaleray---

Explore more