Junglewise Threat Intelligence

CVE-2026-2033: MLflow Tracking Server directory traversal remote code execution

CVE-2026-2033 · Severity: high · CVSS 7.3 · Published 2026-02-20

Technologies: mlflow (PyPI). Vendors: MLflow, PyPI, Red Hat.

Executive brief

MLflow is an open-source platform used by data scientists to manage the machine learning lifecycle, including tracking experiments and storing models. A security vulnerability in its tracking server allows an unauthenticated attacker to remotely execute commands on the server. This could lead to a total compromise of the machine learning environment, including the theft of proprietary models or sensitive training data.

Technical details

A directory traversal vulnerability exists in the MLflow Tracking Server's artifact handler due to insufficient validation of user-supplied file paths. By providing a specially crafted path during artifact operations, a remote, unauthenticated attacker can bypass directory restrictions to perform unauthorized file operations. This flaw can be leveraged to achieve remote code execution in the context of the service account running the MLflow server. The vulnerability is tracked as CVE-2026-2033 and was addressed in MLflow pull request 19260 by implementing stricter path validation for local filestore backends.

Affected products

  • MLflow MLflow Tracking Server 3.1.1 and 5b9c01925c2e2a8cf0951f155a6a468ff99cfe0f
  • Red Hat Red Hat OpenShift AI (RHOAI)

Timeline

  • 2025-07-31: disclosed: Vulnerability reported to vendor
  • 2025-12-10: patched: Fix merged in MLflow GitHub repository
  • 2026-02-13: advisory: ZDI published advisory ZDI-26-105
  • 2026-02-20: advisory: CVE-2026-2033 published in NVD

References

Related threats