PT-2026-97414 · Mlflow · Mlflow

CVE-2026-96804

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MLflow versions 2.1.0 through 3.14.0
Description The statsmodel flavor in MLflow fails to implement the MLFLOW ALLOW PICKLE DESERIALIZATION=False security control within the load model() function. This omission allows a remote attacker to execute arbitrary code by providing a specially crafted MLmodel artifact. Pickle deserialization is a process of converting a byte stream back into a Python object, which can be exploited to run malicious commands if the input is untrusted.
Recommendations Update MLflow to a version later than 3.14.0. As a temporary mitigation, restrict the loading of untrusted MLmodel artifacts until the software is updated.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96804

Affected Products

Mlflow