Description
SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling code execution via pickle REDUCE.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Disable Endpoint
AI Analysis

Impact

SGLang implements an HTTP endpoint at /update_weights_from_tensor that performs Python pickle deserialization without requiring any authentication if no secret keys are configured. The library's SafeUnpickler policy can be subverted because builtins.import and builtins.getattr can be accessed, allowing an attacker to craft a pickle payload that triggers the REDUCE function and creates arbitrary code execution on the host running the SGLang process. This vulnerability results in full remote code execution on the machine and is a classic example of insecure deserialization. The CVSS score is 9.8, indicating a critical level of severity.

Affected Systems

The flaw affects all deployments of the SGLang product where the /update_weights_from_tensor endpoint is available and authentication keys have not been set. No specific product version numbers are enumerated in the data, so any instance that runs the vulnerable code path is considered at risk.

Risk and Exploitability

The absence of authentication means an attacker only needs the ability to send an HTTP request to the target host. The CVSS score is 9.8, the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, yet the combination of unauthenticated access and arbitrary code execution signifies a severe risk. The likely attack vector is a malicious HTTP request; if the endpoint is reachable from the Internet or an untrusted network, exploitation is straightforward and would grant the attacker the same privileges as the SGLang process.

Generated by OpenCVE AI on September 21, 2026 at 04:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable or remove the /update_weights_from_tensor endpoint from the SGLang configuration to eliminate the unauthenticated pickle deserialization path.
  • If removal is not practical, restrict network access to the endpoint so that only trusted IPs or internal networks can contact it, such as through firewall rules or reverse‑proxy authentication.
  • Configure the SGLang service to require authentication keys or client credentials before the endpoint can be invoked, ensuring that only authorized users can trigger deserialization.

Generated by OpenCVE AI on September 21, 2026 at 04:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Sglang
Sglang sglang
Vendors & Products Sglang
Sglang sglang

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Fri, 11 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Fri, 11 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling code execution via pickle REDUCE.
Title CVE-2026-86793
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-09-14T18:51:51.052Z

Reserved: 2026-09-08T11:56:03.107Z

Link: CVE-2026-86793

cve-icon Vulnrichment

Updated: 2026-09-14T18:51:00.896Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:52.427

Modified: 2026-09-14T19:17:51.950

Link: CVE-2026-86793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:00:14Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')