CVE-2026-103270: Missing Authentication for Critical Function in ModelTC LightLLM
LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group to disrupt inference operations and wedge workers on deployments started with --enable_rl.
AI Analysis
Technical Summary
LightLLM through version 1.2.0 exposes reinforcement learning control routes on its public HTTP API without requiring authentication. Attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group without credentials, enabling them to interfere with inference workflows and disrupt deployed workers running with the --enable_rl option.
Potential Impact
Unauthenticated attackers can disrupt inference operations by invoking critical control functions, potentially causing denial of service or degraded performance in deployments using reinforcement learning features. This can wedge worker processes and interrupt normal model operation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict network access to the affected API endpoints to trusted users only and avoid enabling reinforcement learning control routes on publicly accessible interfaces.
CVE-2026-103270: Missing Authentication for Critical Function in ModelTC LightLLM
Description
LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group to disrupt inference operations and wedge workers on deployments started with --enable_rl.
CVSS v4.0
Score 8.7high
Affected software
ModelTC
LightLLM
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
LightLLM through version 1.2.0 exposes reinforcement learning control routes on its public HTTP API without requiring authentication. Attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group without credentials, enabling them to interfere with inference workflows and disrupt deployed workers running with the --enable_rl option.
Potential Impact
Unauthenticated attackers can disrupt inference operations by invoking critical control functions, potentially causing denial of service or degraded performance in deployments using reinforcement learning features. This can wedge worker processes and interrupt normal model operation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict network access to the affected API endpoints to trusted users only and avoid enabling reinforcement learning control routes on publicly accessible interfaces.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-30T10:58:33.573Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abd25252a4e24523d2793e5
Added to database: 09/30/2026, 15:05:09 UTC
Last enriched: 09/30/2026, 15:18:11 UTC
Last updated: 09/30/2026, 16:19:23 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.