Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5189 articles · 192966 vulns · 37/41 feeds (7d)
← Back to list
9.0
CVE-2026-2651PATCHED
mlflow · mlflow/mlflow

Missing Authorization Validation in mlflow/mlflow

Description

A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permission checks for `/mlflow-artifacts/mpu/*` endpoints, enabling attackers to overwrite artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue is resolved in version 3.10.0.

Affected Products

VendorProductVersions
mlflowmlflow/mlflowunspecified

References

  • https://huntr.com/bounties/65beb119-d3e0-4e03-af2f-fa98f78f83dc
  • https://github.com/mlflow/mlflow/commit/d7290811d8f3c95366d80109424edc1fb1ad966f

Related News (1 articles)

Tier C
VulDB85d ago
CVE-2026-2651 | MLflow up to 3.9.x Multipart Upload /mlflow-artifacts/mpu/ authorization (EUVD-2026-31642)
→ No new info (linked only)
CVSS 3.19.0 CRITICAL
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
mlflow@3.11.0rc1
CWECWE-862
PublishedMay 25, 2026
Last enriched85d agov2
Trending Score0
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-64849EXPKEV
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
Trending: 90
HIGHCVE-2026-69148
MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
Trending: 25
MEDIUMCVE-2026-69146
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
Trending: 22
NONECVE-2026-71211
mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint
Trending: 3
CRITICALCVE-2026-4035
Environment Variable Resolution Vulnerability in mlflow/mlflow

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 25, 2026
Discovered by ZDM
May 25, 2026
Updated: affectedVersions
May 25, 2026
Patch Available
Jul 15, 2026

Version History

v2
Last enriched 85d ago
v2Tier C85d ago

Updated affected versions to include 3.9.x and clarified that there is no available exploit.

affectedVersions
via VulDB
v185d ago

Initial creation