VDB
CVE-2026-26931
CVE-2026-26931
PUBLISHED
CVSS 5.699999809265137 MEDIUM
PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_only=True. This issue has been patched in version 2.6.0.
EPSS 0.02% · 6.5th percentile
Risk Scores
CVSS v3.1
5.699999809265137
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.02%
6.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | elastic/beats/v7 | 0, 0, 0 |
| pytorch | pytorch | < 2.6.0 |
| Elastic | Metricbeat | 8.0.0, 8.0.0, 8.0.0 |
Timeline
- Jun 9, 2023 PoC Published
- Jul 15, 2023 PoC Published
- Nov 4, 2023 PoC Published
- Dec 8, 2023 PoC Published
- Mar 1, 2024 PoC Published
- Apr 5, 2024 PoC Published
- Jul 17, 2024 PoC Published
- Apr 18, 2025 PoC Published
- Apr 21, 2025 PoC Published
- Apr 21, 2025 PoC Published
- Apr 21, 2025 PoC Published
- Apr 21, 2025 PoC Published
References
- https://discuss.elastic.co/t/elasticsearch-8-19-8-9-1-8-security-update-esa-2026-18/385534 advisory
- https://discuss.elastic.co/t/kibana-8-19-13-9-2-7-9-3-2-security-update-esa-2026-20/385535 advisory
- https://discuss.elastic.co/t/logstash-8-19-10-9-1-10-9-2-4-security-update-esa-2026-06/385531 advisory
- https://discuss.elastic.co/t/packetbeat-8-19-11-9-2-5-security-update-esa-2026-11/385533 advisory
- https://discuss.elastic.co/t/metricbeat-8-19-13-9-2-5-security-update-esa-2026-09/385532 advisory
- https://discuss.elastic.co/t/kibana-8-19-12-9-2-6-9-3-1-security-update-esa-2026-19/385530 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-26931 advisory
- https://github.com/elastic/beats/commit/de072c4e371eafeb2a42d65b9ad513f666e4ffd7 url
- https://github.com/elastic/beats package
- https://github.com/pytorch/pytorch/security/advisories/GHSA-53q9-r3pm-6pq6 url
- https://lists.debian.org/debian-lts-announce/2025/12/msg00000.html url