
Ray Dashboard has a medium-severity auth bypass (CVE-2026-27482) that lets unauthenticated attackers delete running jobs and shut down Serve apps on Ray 2.53.0 and below if the dashboard is exposed https://www.raxe.ai/labs/advisories/RAXE-2026-026 @RaxeAi
Post summary
The advisory reports CVE-2026-27482, an authentication bypass in Ray Dashboard that lets unauthenticated attackers delete jobs and terminate Serve apps on Ray 2.53.0 and earlier when the dashboard is exposed. No patch, PoC, or evidence of active exploitation is mentioned.
