External risk intelligence

Angel Kryo Deserialization RCE via RPC Endpoint.

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-92785

The vulnerability exists in the master RPC endpoint of Angel, a machine learning platform. While this interface is network-reachable and potentially accessible to unauthenticated attackers, such RPC services in data processing frameworks are typically deployed within internal cluster networks rather than directly exposed to the public internet.

Deserialization

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in Angel, a machine learning platform, that could allow unauthenticated network attackers to execute arbitrary code or cause denial-of-service by sending specially crafted data. The main concern at this time is confirming whether your organization uses this technology and, if so, to what extent.

  • Unauthenticated attackers can run malicious code or crash systems.
  • This impacts machine learning platforms and distributed computing.
  • Confirm relevance and exposure if using this technology.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker on the network can send specially crafted serialized objects to the Angel master RPC endpoint. This could lead to the instantiation of arbitrary classes or the exhaustion of coordinator memory.

  • Network accessible, no authentication required.
  • Sending untrusted serialized objects to RPC endpoint.
  • Arbitrary class instantiation or memory exhaustion.

Live Threat

Current exploitation, exposure, and threat context

The Angel master RPC endpoint could be targeted by unauthenticated network attackers who send crafted serialized objects. This could lead to arbitrary class instantiation, potentially impacting the service's behavior, or cause coordinator memory exhaustion, disrupting the service.

  • Service integrity and availability.
  • Sending crafted serialized objects over network.
  • Service disruption or arbitrary code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Angel ML platform's master RPC endpoint is vulnerable to deserialization of untrusted data, allowing unauthenticated network attackers to instantiate arbitrary classes or cause denial of service. This issue likely falls under the purview of the platform or infrastructure teams responsible for managing the Angel deployment. The immediate practical step is to identify all instances of Angel, determine their network exposure, confirm business criticality, and then assign ownership for remediation planning based on assessed risk.

  • Platform or infrastructure teams should own the issue.
  • Verify Angel's network exposure and criticality.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Angel platform?

Angel is a machine learning framework designed for large-scale distributed computing. It is typically used by data engineering and machine learning teams to perform complex model training and handle distributed data processing tasks across compute clusters.

What does deserialization vulnerability mean for CVE-2026-92785?

This vulnerability is classified as CWE-502, Deserialization of Untrusted Data. It occurs because the software reconstructs objects from incoming network data using the Kryo library without checking if those objects are safe. Because there is no allowlist, an attacker can trick the system into creating unauthorized objects that perform unintended actions or consume all available memory.

How can an attacker trigger this issue?

An unauthenticated attacker triggers this flaw by sending a specially crafted serialized object to the master RPC endpoint of the Angel service. Simply connecting to the network is not enough; the attacker must specifically format data to exploit the way the master RPC service processes objects. Legitimate traffic that does not use the specific `setAlgoMetrics` payload structure does not trigger this vulnerability.

Why should I be concerned about CVE-2026-92785?

According to Halo Surface Signal, the master RPC endpoint is network-reachable, meaning it could be targeted if reachable by an attacker. While these services are often kept within internal data processing networks, any instance accessible over the network is at risk of unauthorized code execution or service disruption.

What are the first steps to address this vulnerability?

Start by identifying all instances of Angel deployed within your environment. Once you have an inventory, verify the network configuration for each master RPC endpoint to understand if they are accessible from untrusted segments. Finally, coordinate with your infrastructure or platform teams to prioritize these instances based on their business criticality and network exposure.

References