Skip to content
CVE Alert: CVE-2026-92786 – lightgbm-org

CVE Alert: CVE-2026-92786 – lightgbm-org

Redpacketsecurity admin September 17, 2026

LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers can craft malicious model files with invalid node references that trigger out-of-bounds writes at attacker-chosen offsets in the leaf_depth_ buffer during feature contribution computation.

This is a high-impact vulnerability requiring prompt remediation, although immediate exploitation urgency cannot be confirmed because KEV, SSVC, PoC and EPSS indicators are not provided.

Successful exploitation could corrupt process memory, causing denial of service or potentially enabling code execution within the service, notebook, pipeline or analyst workstation processing the model. The realistic attacker goal is to submit or replace a malicious model and compromise an environment that treats model artefacts as trusted data.

### Most likely attack path

The path is local (AV:L), low complexity (AC:L), requires no privileges (PR:N) and depends on passive user interaction (UI:P), such as an analyst, job or service loading an untrusted model. Scope is unchanged, so exploitation is primarily confined to the affected process and its host privileges, though those privileges may enable access to data, credentials or connected ML infrastructure.

### Who is most exposed

Organisations accepting models from customers, partners, public repositories or shared research environments are most exposed. Risk is higher in automated inference, SHAP explainability, CI/CD and notebook platforms where model files are loaded without manual review.

Alert on unexpected model-file creation, replacement or downloads in inference and analytics hosts.

Correlate model loading with crashes, segmentation faults, heap corruption or abrupt worker restarts.

Monitor child-process creation, shell activity and unusual outbound connections from ML services.

Review provenance, hashes and submitter identity for imported model artefacts.

### Mitigation and prioritisation

Upgrade to the vendor-fixed release as soon as validated; do not rely on version-based filtering alone if packages are bundled.

Until patched, block untrusted model uploads and isolate parsing or explanation jobs in least-privileged sandboxes.

Enforce signed artefacts, allow-listed repositories and malware scanning before model ingestion.

Treat as priority 1 if KEV is true or EPSS is at least 0.5; absent those data, confirm exposure and exploitation telemetry urgently.

Test patched workflows and schedule controlled restarts where long-running inference services require change windows.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

Platforms (1)