← Vulnerability feed

Vulnerability record · CVE-2023-48022 · published 28 November 2023

CVE-2023-48022: Anyscale Ray job submission API allows unauthenticated remote code execution

Anyscale · Ray

Anyscale Ray versions 2.6.3 and 2.8.0 expose a job submission API that lets a remote attacker execute arbitrary code. The vendor disputes the report, stating Ray is not meant to run outside a strictly controlled network and that token authentication is available from version 2.52.0 onward. Because the API is reachable over the network with no credentials, any exposed Ray dashboard or job endpoint is a direct code execution path.

9.8 CVSS 3.1 Critical EPSS 84% · top 0.3% CWE-918 · Server-side request forgery (SSRF)
9.8CVSS 3.1 base score
84%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
9References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment. (Also, within that environment, customers at version 2.52.0 and later can choose to use token authentication.)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS of 9.8 and very high EPSS, with public exploit tooling already circulating.

What it is

Anyscale Ray versions 2.6.3 and 2.8.0 expose a job submission API that lets a remote attacker execute arbitrary code. The vendor disputes the report, stating Ray is not meant to run outside a strictly controlled network and that token authentication is available from version 2.52.0 onward. Because the API is reachable over the network with no credentials, any exposed Ray dashboard or job endpoint is a direct code execution path.

Impact

An attacker gains arbitrary code execution on the Ray node, which typically means full control of the host, its data and any credentials or cluster resources it can reach. In a shared or internet-facing deployment this can pivot into the wider environment.

Attack surface

Reached over the network via the Ray job submission API (CVSS AV:N, PR:N, UI:N), so no authentication and no user interaction are required. The flaw is only exploitable where Ray is exposed beyond a strictly controlled network, which the vendor says is unsupported.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.83942, 99.7th percentile) and public exploit write-ups exist, including a Bishop Fox advisory tagged Exploit and a Vicarius post on the ShadowRay campaign. This indicates active, practical exploitation rather than a theoretical issue.

What to do

  • Upgrade Ray to a version with token authentication (2.52.0 or later) and enable it, or apply the vendor's current security guidance.
  • Never expose the Ray dashboard or job submission API to untrusted networks; bind to localhost or a private interface and restrict with firewall rules or a VPN.
  • Require authentication and authorization in front of any Ray endpoint using a reverse proxy or service mesh if Ray itself cannot enforce it.
  • Isolate Ray clusters in a dedicated, segmented network with least-privilege credentials and no access to sensitive internal services.
  • Monitor for unexpected job submissions and audit cluster nodes for unauthorized processes or outbound connections.

Detection

  • Alert on POST requests to Ray job submission endpoints from unexpected source IPs or outside the cluster network.
  • Monitor Ray dashboard and job API logs for job submissions that were not initiated by known users or automation.
  • Hunt for new processes, reverse shells or unusual outbound connections originating from Ray worker nodes.
  • Track Ray versions in inventory and flag any deployment below 2.52.0 that is network-reachable.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-48022 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed9.1CVE-2023-48023Anyscale ray server-side request forgery (ssrf) vulnerabilityAnyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its docu…EPSS 35%8.9CVE-2026-41486Anyscale ray code injection vulnerabilityRay is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types (ray.data.arrow_tensor, ra…EPSS 0.70%8.7CVE-2026-32981Anyscale ray path traversal vulnerabilityA path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and san…EPSS 1.0%8.6CVE-2026-57516Anyscale ray deserialization of untrusted data vulnerabilityRay prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution …EPSS 0.86%6.5CVE-2026-27482Anyscale ray vulnerabilityRay is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but does not cover DELETE, and key…EPSS 0.40%10.0CVE-2026-83548SonicWall SMA1000 pre-auth SSRF via alternate access pathThe SMA1000 Appliance Work Place interface exposes an unintended alternate access path that allows server-side request forgery before authentication.…KEVEPSS 8.8%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed

Source: NIST National Vulnerability Database (record CVE-2023-48022), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.