www.vulncheck.com Critical CVE-2026-92786 in LightGBM Allows Out-of-Bounds Memory Writes
Article Content
- •CVE-2026-92786 allows out-of-bounds writes in LightGBM versions up to 4.7.0.
- •Organizations using untrusted model files are at high risk of exploitation.
- •Immediate remediation is recommended, including upgrading and blocking untrusted uploads.
LightGBM versions up to 4.7.0 contain a critical vulnerability (CVE-2026-92786) that fails to validate child and split array values when parsing text models. This flaw allows attackers to craft malicious model files that can trigger out-of-bounds writes, potentially leading to memory corruption, denial of service, or even code execution. Organizations that accept models from external sources, especially in automated inference environments, are particularly at risk. The vulnerability was published on September 16, 2026, and requires immediate remediation, although the urgency of exploitation has not been confirmed. Mitigation strategies include upgrading to the fixed release and blocking untrusted model uploads. Monitoring for unusual model file activity is also recommended. The vulnerability's exploitation path is local, low complexity, and requires no privileges, making it accessible to many potential attackers.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-92786 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…