CVE-2026-69148 – MLflow

CVSS 7.1 IMPORTANT Zero Day – Immediate Deployment

“These flaws can expose internal services and cross user access boundaries in MLflow deployments.”

MLflow 3.15.0 fixes two serious vulnerabilities. CVE-2026-64849 is an unauthenticated server-side request forgery issue that can follow redirects to internal systems or cloud metadata services and return response content to an attacker. CVE-2026-64849 has a CVSS score of 9.3, Critical severity, and active exploitation is confirmed.

CVE-2026-69148 allows an authenticated user to reference another user’s artifact directory and retrieve files without the required read permission. CVE-2026-69148 has a CVSS score of 7.1, High severity. Public proof-of-concept material is confirmed.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-862
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.