PT-2026-53097 · Mlflow · Mlflow

·

CVE-2026-13484

·

Published

2026-06-28

·

Updated

2026-07-08

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MLflow versions up to 4666cffc7912ea606d592fc38d6a75e2935f65e7
Description An issue exists within the Experiment-scoped Label Schema CRUD API where a function lacks proper authorization. This allows a remote attacker to perform unauthorized manipulations, although the attack is characterized by high complexity and is difficult to exploit.
Recommendations Update to a version where the labeling schema pull request has been merged and authorization handlers have been implemented.

Exploit

Fix

DoS

Missing Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MLFLOW-2026-13484
CVE-2026-13484

Affected Products

Mlflow