PT-2026-94063 · Lightgbm Org+1 · Lightgbm

·

CVE-2026-92786

·

Published

2026-09-16

·

Updated

2026-09-21

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions LightGBM versions prior to 4.7.1
Description Failure to validate child and split array values when parsing text models allows for out-of-bounds memory writes during SHAP (SHapley Additive exPlanations, a method used to explain the output of machine learning models) prediction. An attacker can create malicious model files containing invalid node references to trigger these writes at specific offsets within the leaf depth buffer during the computation of feature contributions.
Recommendations Update LightGBM to version 4.7.1 or later.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92786

Affected Products

Lightgbm