- Products & ServicesProducts & Services
- SolutionsSolutions
- PricingPricing
- CompanyCompany
- ResourcesResources
en
en
Severity across 76 analyzed records
As of 09/11/2026, mlflow recorded 6 security vulnerabilities in the last 90 days across 2 products, including 5 rated High or above and 1 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, MLflow had the most security vulnerabilities in the mlflow ecosystem, with 5 vulnerabilities—approximately 83.33% of the provider's total vulnerabilities during this period.
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-79721CVE-2026-79721 | Exploitation statusNot known exploited | FixNot confirmed | Affected productMLflow | Published09/08/2026 | SeverityHigh |
CVE-2026-69146MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth | Exploitation statusPublic exploit | FixYes | Affected productMLflow | Published08/17/2026 | SeverityMedium |
CVE-2026-69148MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id | Exploitation statusPublic exploit | FixYes | Affected productMLflow | Published08/17/2026 | SeverityHigh |
CVE-2026-64849MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) | Exploitation statusKEV | FixYes | Affected productMLflow | Published08/17/2026 | SeverityCritical |
CVE-2026-71211mlflow - Unvalidated Gateway Secret api_base Enables SSRF via Gateway Proxy Endpoint | Exploitation statusNot known exploited | FixNot confirmed | Affected productMLflow | Published08/05/2026 | SeverityHigh |
CVE-2026-8147Authorization Bypass in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published07/02/2026 | SeverityHigh |
CVE-2026-4035Environment Variable Resolution Vulnerability in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published06/03/2026 | SeverityCritical |
CVE-2026-3198Improper Access Control in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productmlflow/mlflow | Published06/02/2026 | SeverityMedium |
CVE-2026-2651Missing Authorization Validation in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published05/25/2026 | SeverityCritical |
CVE-2026-2734Authorization Bypass in SearchModelVersions in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published05/21/2026 | SeverityMedium |
CVE-2026-2611Improper Origin Validation in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published05/19/2026 | SeverityCritical |
CVE-2026-4137Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published05/18/2026 | SeverityHigh |
CVE-2026-2652Authentication Bypass in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published05/15/2026 | SeverityHigh |
CVE-2026-2614Arbitrary File Read via Prompt Tag Source Validation Bypass in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published05/11/2026 | SeverityHigh |
CVE-2026-2393Server-Side Request Forgery (SSRF) in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published05/11/2026 | SeverityHigh |
CVE-2026-33866Authorization Bypass in MLflow AJAX Endpoint | Exploitation statusPublic exploit | FixYes | Affected productMLflow | Published04/07/2026 | SeverityMedium |
CVE-2026-33865Stored XSS via unsafe YAML parsing in MLflow | Exploitation statusPublic exploit | FixYes | Affected productMLflow | Published04/07/2026 | SeverityMedium |
CVE-2026-0545Missing Authentication for Critical Function in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productmlflow/mlflow | Published04/03/2026 | SeverityCritical |
CVE-2026-0596Command Injection in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productmlflow/mlflow | Published03/31/2026 | SeverityCritical |
CVE-2025-15379Command Injection in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published03/30/2026 | SeverityCritical |
CVE-2025-15036Path Traversal Vulnerability in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published03/30/2026 | SeverityCritical |
CVE-2025-15381Unauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflow | Exploitation statusNot known exploited | FixNot confirmed | Affected productmlflow/mlflow | Published03/27/2026 | SeverityHigh |
CVE-2025-15031Path Traversal Vulnerability in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productmlflow/mlflow | Published03/18/2026 | SeverityHigh |
CVE-2025-14287Command Injection in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productmlflow/mlflow | Published03/15/2026 | SeverityHigh |
CVE-2026-2635MLflow Use of Default Password Authentication Bypass Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productMLflow | Published02/20/2026 | SeverityCritical |
CVE-2026-2033MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productMLflow | Published02/20/2026 | SeverityHigh |
CVE-2025-10279Privilege Escalation in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published02/02/2026 | SeverityHigh |
CVE-2025-14279DNS Rebinding Vulnerability in mlflow/mlflow | Exploitation statusNot known exploited | FixYes | Affected productmlflow/mlflow | Published01/12/2026 | SeverityHigh |
CVE-2025-11200MLflow Weak Password Requirements Authentication Bypass Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productMLflow | Published10/29/2025 | SeverityHigh |
CVE-2025-11201MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability | Exploitation statusNot known exploited | FixNot confirmed | Affected productMLflow | Published10/29/2025 | SeverityHigh |
CVE-2025-0453Denial of Service through Batched Queries in GraphQL in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productmlflow/mlflow | Published03/20/2025 | SeverityMedium |
CVE-2025-1474Weak Password Requirements in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published03/20/2025 | SeverityLow |
CVE-2025-1473CSRF in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published03/20/2025 | SeverityMedium |
CVE-2024-8859Path Traversal in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published03/20/2025 | SeverityHigh |
CVE-2024-6838Uncontrolled Resource Consumption in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productmlflow/mlflow | Published03/20/2025 | SeverityMedium |
CVE-2024-2928Local File Inclusion (LFI) via URI Fragment Parsing in mlflow/mlflow | Exploitation statusNot known exploited | FixYes | Affected productmlflow/mlflow | Published06/06/2024 | SeverityHigh |
CVE-2024-0520Remote Code Execution due to Full Controlled File Write in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published06/06/2024 | SeverityCritical |
CVE-2024-3099Denial of Service and Data Model Poisoning via URL Encoding in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productmlflow/mlflow | Published06/06/2024 | SeverityMedium |
CVE-2024-37061CVE-2024-37061 | Exploitation statusPublic exploit | FixNot confirmed | Affected productMLflow | Published06/04/2024 | SeverityHigh |
CVE-2024-37060CVE-2024-37060 | Exploitation statusNot known exploited | FixNot confirmed | Affected productMLflow | Published06/04/2024 | SeverityHigh |
CVE-2024-37059CVE-2024-37059 | Exploitation statusNot known exploited | FixNot confirmed | Affected productMLflow | Published06/04/2024 | SeverityHigh |
CVE-2024-37058CVE-2024-37058 | Exploitation statusPublic exploit | FixNot confirmed | Affected productMLflow | Published06/04/2024 | SeverityHigh |
CVE-2024-37057CVE-2024-37057 | Exploitation statusPublic exploit | FixNot confirmed | Affected productMLflow | Published06/04/2024 | SeverityHigh |
CVE-2024-37056CVE-2024-37056 | Exploitation statusNot known exploited | FixNot confirmed | Affected productMLflow | Published06/04/2024 | SeverityHigh |
CVE-2024-37055CVE-2024-37055 | Exploitation statusNot known exploited | FixNot confirmed | Affected productMLflow | Published06/04/2024 | SeverityHigh |
CVE-2024-37054CVE-2024-37054 | Exploitation statusNot known exploited | FixNot confirmed | Affected productMLflow | Published06/04/2024 | SeverityHigh |
CVE-2024-37053CVE-2024-37053 | Exploitation statusNot known exploited | FixNot confirmed | Affected productMLflow | Published06/04/2024 | SeverityHigh |
CVE-2024-37052CVE-2024-37052 | Exploitation statusNot known exploited | FixNot confirmed | Affected productMLflow | Published06/04/2024 | SeverityHigh |
CVE-2024-4263Improper Access Control in mlflow/mlflow | Exploitation statusNot known exploited | FixYes | Affected productmlflow/mlflow | Published05/16/2024 | SeverityMedium |
CVE-2024-3848Path Traversal Bypass in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published05/16/2024 | SeverityHigh |
CVE-2024-3573Local File Inclusion (LFI) via Scheme Confusion in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published04/16/2024 | SeverityCritical |
CVE-2024-1558Path Traversal Vulnerability in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productmlflow/mlflow | Published04/16/2024 | SeverityHigh |
CVE-2024-1594Local File Read via Path Traversal in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productmlflow/mlflow | Published04/16/2024 | SeverityHigh |
CVE-2024-1593Path Traversal via Parameter Smuggling in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productmlflow/mlflow | Published04/16/2024 | SeverityHigh |
CVE-2024-1483Path Traversal Vulnerability in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productmlflow/mlflow | Published04/16/2024 | SeverityHigh |
CVE-2024-1560Path Traversal Vulnerability in mlflow/mlflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productmlflow/mlflow | Published04/16/2024 | SeverityHigh |
CVE-2023-6977Path Traversal: '\..\filename' | Exploitation statusNot confirmed | FixYes | Affected productmlflow/mlflow | Published12/20/2023 | SeverityCritical |
CVE-2023-6976Unrestricted Upload of File with Dangerous Type | Exploitation statusNot confirmed | FixYes | Affected productmlflow/mlflow | Published12/20/2023 | SeverityHigh |
CVE-2023-6975Path Traversal: '\..\filename' | Exploitation statusNot confirmed | FixYes | Affected productmlflow/mlflow | Published12/20/2023 | SeverityCritical |
CVE-2023-6974Server-Side Request Forgery (SSRF) | Exploitation statusNot confirmed | FixYes | Affected productmlflow/mlflow | Published12/20/2023 | SeverityHigh |
CVE-2023-6940Command Injection | Exploitation statusNot known exploited | FixYes | Affected productmlflow/mlflow | Published12/19/2023 | SeverityCritical |
CVE-2023-6909Path Traversal: '\..\filename' in mlflow/mlflow | Exploitation statusNot confirmed | FixYes | Affected productmlflow/mlflow | Published12/18/2023 | SeverityHigh |
CVE-2023-6831Path Traversal: '\..\filename' in mlflow/mlflow | Exploitation statusNot confirmed | FixYes | Affected productmlflow/mlflow | Published12/15/2023 | SeverityHigh |
CVE-2023-6753Path Traversal in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published12/13/2023 | SeverityCritical |
CVE-2023-6709Improper Neutralization of Special Elements Used in a Template Engine in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published12/12/2023 | SeverityCritical |
CVE-2023-6568Reflected XSS via Content-Type Header in mlflow/mlflow | Exploitation statusNot confirmed | FixYes | Affected productmlflow/mlflow | Published12/07/2023 | SeverityMedium |
CVE-2023-6014MLflow Authentication Bypass | Exploitation statusPublic exploit | FixNot confirmed | Affected productmlflow/mlflow | Published11/16/2023 | SeverityCritical |
CVE-2023-6015MLflow Arbitrary File Upload | Exploitation statusNot confirmed | FixNot confirmed | Affected productmlflow/mlflow | Published11/16/2023 | SeverityCritical |
CVE-2023-6018MLflow Arbitrary File Write | Exploitation statusNot confirmed | FixNot confirmed | Affected productmlflow/mlflow | Published11/16/2023 | SeverityCritical |
CVE-2023-4033OS Command Injection in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published08/01/2023 | SeverityHigh |
CVE-2023-3765Absolute Path Traversal in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published07/19/2023 | SeverityCritical |
CVE-2023-2780Path Traversal: '\..\filename' in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published05/17/2023 | SeverityCritical |
CVE-2023-2356Relative Path Traversal in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published04/28/2023 | SeverityCritical |
CVE-2023-1177Path Traversal: '\..\filename' in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published03/24/2023 | SeverityCritical |
CVE-2023-1176Absolute Path Traversal in mlflow/mlflow | Exploitation statusPublic exploit | FixYes | Affected productmlflow/mlflow | Published03/24/2023 | SeverityMedium |
CVE-2022-0736Insecure Temporary File in mlflow/mlflow | Exploitation statusNot confirmed | FixYes | Affected productmlflow/mlflow | Published02/23/2022 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan