Skip to content
Critical CVE-2026-92786 in LightGBM Allows Out-of-Bounds Memory Writes

Critical CVE-2026-92786 in LightGBM Allows Out-of-Bounds Memory Writes

First seen 17 Sep 2026, 21:59 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 22:01 UTC
  • CVE-2026-92786 allows out-of-bounds writes in LightGBM versions up to 4.7.0.
  • Organizations using untrusted model files are at high risk of exploitation.
  • Immediate remediation is recommended, including upgrading and blocking untrusted uploads.

LightGBM versions up to 4.7.0 contain a critical vulnerability (CVE-2026-92786) that fails to validate child and split array values when parsing text models. This flaw allows attackers to craft malicious model files that can trigger out-of-bounds writes, potentially leading to memory corruption, denial of service, or even code execution. Organizations that accept models from external sources, especially in automated inference environments, are particularly at risk. The vulnerability was published on September 16, 2026, and requires immediate remediation, although the urgency of exploitation has not been confirmed. Mitigation strategies include upgrading to the fixed release and blocking untrusted model uploads. Monitoring for unusual model file activity is also recommended. The vulnerability's exploitation path is local, low complexity, and requires no privileges, making it accessible to many potential attackers.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
CVE-2026-92786 published
LightGBM vulnerability disclosed, affecting versions up to 4.7.0 with potential for memory corruption.
Redpacketsecurity
2026-09-17
Vulnerability alert issued
Security advisories highlight the need for immediate action to mitigate the LightGBM vulnerability.
www.vulncheck.com

More articles in this cluster (2)

Following this threat?

Track CVE-2026-92786 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed