LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-85663

Published
CVSS9.8
Severitycritical
WeaknessCWE-306
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers can register clients, instantiate Repo resources, and invoke arbitrary methods to read experiments or delete runs.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-85663

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-85663.