MLflow Vulnerability Exploited for Cloud Credential Theft
Reported exploitedMLflowOur summary
Threat actors are actively leveraging an unauthenticated server-side request forgery (SSRF) flaw in MLflow, tracked as CVE-2026-64849, to exfiltrate cloud credentials and secrets. The vulnerability stems from the MLflow Tracking Server exposing model-registry webhook APIs without proper authentication, allowing attackers to bypass SSRF protections introduced in version 3.10.0 and directly access cloud metadata services. With a CVSS score of 9.3, this defect affects all MLflow versions prior to 3.15.0 and has been added to the CISA Known Exploited Vulnerabilities catalog, prompting urgent remediation across affected systems.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.