CVE-2026-2492

EUVD-2026-7768
TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TensorFlow. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the handling of plugins. The application loads plugins from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user. Was ZDI-CAN-25480.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
zdiCNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 16.92%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat OpenShift AI 2.25
1776243249 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 2.25
1776319453 ≤
𝑥
< *
ADP
tensorflowtensorflow
2.17.0
CNA
Debian logo
Debian Releases
Debian Product
Codename
tensorflow
forky
2.14.1+dfsg-3.1
fixed
sid
2.14.1+dfsg-3.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tensorflow
jammy
dne
noble
dne
questing
ignored
resolute
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
tensorflow
Azure Linux 3.0
0:2.16.1-11.azl3
fixed