Junglewise Threat Intelligence

CVE-2026-85663: Aim remote tracking server authentication bypass and arbitrary method invocation

CVE-2026-85663 · Severity: critical · CVSS 9.8 · Published 2026-09-04

Technologies: Aim. Vendors: Aim.

Executive brief

Aim is an open-source experiment tracking platform used by data scientists to manage and compare machine learning experiments. The remote tracking server fails to authenticate incoming requests and allows unauthenticated attackers to invoke arbitrary Python methods through unsafe use of getattr(), enabling attackers to read sensitive experiments, delete runs, or access underlying data without any credentials.

Technical details

The vulnerability is a combination of missing authentication and unsafe object method dispatch. The TrackingRouter in the remote server fails to validate authentication on tracking endpoints and uses getattr() without an allowlist to dynamically invoke methods on registered resource objects (Repo, StructuredRun, etc.). An unauthenticated attacker can register clients, instantiate Repo resources, and chain method calls to invoke arbitrary public methods on the resource objects, reading sensitive experiment metadata or deleting runs. The vulnerability affects the /tracking endpoint and requires network access to the Aim tracking server; no authentication or special preconditions are needed. No patch information is provided in the advisory.

Affected products

  • Aim Aim 3.29.1

Timeline

  • 2026-09-04: disclosed

References

Related threats