{"id":"PYSEC-2026-2523","summary":"Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow","details":"Improper buffer restrictions in the Intel(R) Optimization for Tensorflow software before version 2.12 may allow an authenticated user to potentially enable escalation of privilege via local access.","aliases":["CVE-2023-27506","GHSA-m2f8-v8q4-3m59","PYSEC-2026-1465","PYSEC-2026-3385"],"modified":"2026-07-13T16:43:39.480249482Z","published":"2026-07-13T14:20:01.577384Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-27506"},{"type":"WEB","url":"http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00840.html"},{"type":"PACKAGE","url":"https://pypi.org/project/intel-tensorflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-m2f8-v8q4-3m59"}],"affected":[{"package":{"name":"intel-tensorflow","ecosystem":"PyPI","purl":"pkg:pypi/intel-tensorflow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.12"}]}],"versions":["0.0.1","1.12.0","1.13.1","1.13.2","1.14.0","1.15.0","1.15.2","2.0.0","2.0.1","2.1.0","2.1.1","2.10.0","2.11.0","2.11.dev202242","2.2.0","2.3.0","2.4.0","2.5.0","2.6.0","2.7.0","2.8.0","2.9.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/intel-tensorflow/PYSEC-2026-2523.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L"}]}