CVE-2026-27482

MEDIUM

Ray < 2.54.0 - Unauthenticated Job Deletion via Dashboard DELETE Endpoint

Title source: llm
STIX 2.1

Description

Ray is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but does not cover DELETE, and key DELETE endpoints are unauthenticated by default. If the dashboard/agent is reachable (e.g., --dashboard-host=0.0.0.0), a web page via DNS rebinding or same-network access can issue DELETE requests that shut down Serve or delete jobs without user interaction. This is a drive-by availability impact. The fix for this vulnerability is to update to Ray 2.54.0 or higher.

Scores

CVSS v3 5.9
EPSS 0.0006
EPSS Percentile 18.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-396
Status published
Products (2)
anyscale/ray < 2.54.0
pypi/ray 0 - 2.54.0PyPI
Published Feb 21, 2026
Tracked Since Feb 21, 2026