CVE-2026-24693: Protection mechanism failure for some Intel(R) oneCCL Bindings for PyTorch before version v2.8.0 within Ring 3: User App
Summary
Intel's oneCCL Bindings for PyTorch (a library that helps PyTorch run on Intel hardware) versions before v2.8.0 have a flaw in their protection mechanism that could let an unprivileged user gain elevated privileges (privilege escalation, meaning gaining admin-level access they shouldn't have). An attacker could exploit this through local access with minimal effort and some basic user interaction.
Solution / Mitigation
Update Intel(R) oneCCL Bindings for PyTorch to version v2.8.0 or later.
Vulnerability Details
EPSS: 0.0%
August 11, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-24693
First tracked: August 11, 2026 at 02:09 PM
Classified by LLM (prompt v3) · confidence: 85%