Description
Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate arbitrary classes or exhaust coordinator memory by sending crafted serialized objects to the master RPC endpoint.
Published: 2026-09-16
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Angel up to version 3.3.0 uses Kryo for deserialization of arbitrary classes without class registration or allowlist. An unauthenticated attacker who can reach the master RPC endpoint can send a crafted serialized payload that causes the JVM to instantiate arbitrary classes. This can lead to remote code execution under the permissions of the master node or result in denial of service through memory exhaustion.

Affected Systems

The vulnerability affects Angel-ML Angel platforms running version 3.3.0 or earlier. Systems exposed to untrusted networks that communicate with the master RPC endpoint are vulnerable.

Risk and Exploitability

The CVSS score of 9.2 indicates high severity. An EPSS score of less than 1% shows that exploitation is currently rare, and the vulnerability is not yet listed in the CISA KEV catalog. However, the attack vector is network‑based and unauthenticated; an attacker only needs connectivity to the master RPC port to deliver the malicious payload.

Generated by OpenCVE AI on September 17, 2026 at 21:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict network access to the master RPC endpoint so only trusted IP addresses can reach it; this blocks unauthenticated attackers from sending malicious payloads.
  • Upgrade Angel-ML Angel to a version newer than 3.3.0 that includes a fixed Kryo deserialization filter; check the vendor’s release notes for the fix.
  • Deploy network monitoring or intrusion detection that flags abnormal Kryo‑serialized data targeting the master RPC service to detect attempted exploitation attempts.

Generated by OpenCVE AI on September 17, 2026 at 21:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Angel-ml
Angel-ml angel
Vendors & Products Angel-ml
Angel-ml angel

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate arbitrary classes or exhaust coordinator memory by sending crafted serialized objects to the master RPC endpoint.
Title Angel through 3.3.0 Unauthenticated Kryo Deserialization of Arbitrary Classes
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T15:03:38.116Z

Reserved: 2026-09-16T19:22:55.254Z

Link: CVE-2026-92785

cve-icon Vulnrichment

Updated: 2026-09-17T15:03:34.856Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:27.730

Modified: 2026-09-24T20:48:01.433

Link: CVE-2026-92785

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:03:15Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data