CVE-2026-69148 – MLflow
CVSS 7.1
IMPORTANT
Zero Day – Immediate Deployment
“These flaws can expose internal services and cross user access boundaries in MLflow deployments.”
MLflow 3.15.0 fixes two serious vulnerabilities. CVE-2026-64849 is an unauthenticated server-side request forgery issue that can follow redirects to internal systems or cloud metadata services and return response content to an attacker. CVE-2026-64849 has a CVSS score of 9.3, Critical severity, and active exploitation is confirmed.
CVE-2026-69148 allows an authenticated user to reference another user’s artifact directory and retrieve files without the required read permission. CVE-2026-69148 has a CVSS score of 7.1, High severity. Public proof-of-concept material is confirmed.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-862
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.