CVE-2026-64849 – MLflow
CVSS 9.3
CRITICAL
Zero Day – Immediate Deployment
“These flaws can expose internal services and cross user access boundaries in MLflow deployments.”
MLflow 3.15.0 fixes two serious vulnerabilities. CVE-2026-64849 is an unauthenticated server-side request forgery issue that can follow redirects to internal systems or cloud metadata services and return response content to an attacker. CVE-2026-64849 has a CVSS score of 9.3, Critical severity, and active exploitation is confirmed.
CVE-2026-69148 allows an authenticated user to reference another user’s artifact directory and retrieve files without the required read permission. CVE-2026-69148 has a CVSS score of 7.1, High severity. Public proof-of-concept material is confirmed.
Key Details
- Affected Product
- Lfprojects Mlflow
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-918
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.