CVE Tools

MLflow Vulnerability Exploited for Cloud Credential Theft

SecurityWeekBy Ionut Arghire

Reported exploitedMLflow

Our summary

Threat actors are actively leveraging an unauthenticated server-side request forgery (SSRF) flaw in MLflow, tracked as CVE-2026-64849, to exfiltrate cloud credentials and secrets. The vulnerability stems from the MLflow Tracking Server exposing model-registry webhook APIs without proper authentication, allowing attackers to bypass SSRF protections introduced in version 3.10.0 and directly access cloud metadata services. With a CVSS score of 9.3, this defect affects all MLflow versions prior to 3.15.0 and has been added to the CISA Known Exploited Vulnerabilities catalog, prompting urgent remediation across affected systems.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store