{"id":"PYSEC-2026-3385","summary":"Authenticated Local Privilege Escalation vulnerability in Intel Optimization for Tensorflow","details":"Improper buffer restrictions in the Intel(R) Optimization for Tensorflow software before version 2.12 may allow an authenticated user to potentially enable escalation of privilege via local access.","aliases":["CVE-2023-27506","GHSA-m2f8-v8q4-3m59","PYSEC-2026-1465","PYSEC-2026-2523"],"modified":"2026-07-13T16:43:39.480249482Z","published":"2026-07-13T14:20:01.735062Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-27506"},{"type":"WEB","url":"http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00840.html"},{"type":"PACKAGE","url":"https://pypi.org/project/tensorflow-intel"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-m2f8-v8q4-3m59"}],"affected":[{"package":{"name":"tensorflow-intel","ecosystem":"PyPI","purl":"pkg:pypi/tensorflow-intel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.12"}]}],"versions":["0.0.1","2.10.0","2.10.0.dev20220728","2.10.0rc0","2.10.0rc1","2.10.0rc2","2.10.0rc3","2.10.1","2.11.0","2.11.0rc0","2.11.0rc1","2.11.0rc2","2.11.1","2.12.0rc0","2.12.0rc1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/tensorflow-intel/PYSEC-2026-3385.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L"}]}