Vendor
MLflow vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 23 vulnerabilities in MLflow: 2 in the last 7 days and 5 in the last 90 days, 7 of them critical and 1 exploited in the wild. The most recent, CVE-2026-96804, was published on 23 September 2026.
- Last 7 days
- 2
- Last 90 days
- 5
- Critical, all time
- 7
- Exploited in the wild
- 1
About MLflow
MLflow is an open-source platform for managing the end-to-end machine learning lifecycle.
Latest MLflow vulnerabilities
- CVE-2026-96804: MLflow statsmodels flavor arbitrary code execution via pickle deserializationhighCVSS 8.8EPSS 0.4%
- CVE-2026-96775: MLflow dspy flavor insufficient pickle deserialization controlhighCVSS 8.8EPSS 0.4%
- CVE-2026-64849: MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to…criticalexploited in the wildCVSS 9.3EPSS 9.8%
- CVE-2026-71211: MLflow AI Gateway SSRF via unvalidated api_basehighCVSS 7.1EPSS 0.3%
- CVE-2026-8147: MLflow improper authorization in trace API endpointshighCVSS 8.1EPSS 0.5%
- CVE-2026-13484: MLflow missing authorization in Label Schema CRUD APImediumCVSS 5
- CVE-2026-4035: MLflow AI Gateway credential exfiltration via environment variable resolutioncriticalCVSS 9.1EPSS 0.7%
- CVE-2026-3198: MLflow improper access control in Gateway API list endpointsmediumCVSS 6.5EPSS 0.4%
- CVE-2026-2651: MLflow missing authorization in multipart upload endpointscriticalCVSS 9EPSS 0.5%
- CVE-2026-2734: MLflow improper access control in SearchModelVersions APImediumCVSS 6.5EPSS 0.5%
- CVE-2026-2611: MLflow MLflow Assistant improper origin validation in /ajax-apicriticalCVSS 9.6EPSS 0.4%
- CVE-2026-4137: MLflow arbitrary code execution via insecure temporary directory permissionshighCVSS 7EPSS 0.2%
- CVE-2026-2652: MLflow authentication bypass in FastAPI routeshighCVSS 8.6EPSS 1.4%
- CVE-2026-2614: MLflow arbitrary file read via prompt tag validation bypasshighCVSS 7.5EPSS 3.2%
- CVE-2026-33865: MLflow stored XSS via unsafe YAML parsing in MLmodel artifactsmediumCVSS 5.4EPSS 0.3%
- CVE-2026-33866: MLflow authorization bypass in model artifact download endpointmediumCVSS 4.3EPSS 0.4%
- CVE-2026-0545: MLflow authentication bypass in FastAPI job endpointscriticalCVSS 9.8EPSS 4.4%
- CVE-2026-0596: MLflow command injection in model serving via model_uricriticalCVSS 9.6EPSS 1.3%
- CVE-2025-15036: MLflow path traversal in extract_archive_to_dircriticalCVSS 10EPSS 0.6%
- CVE-2025-15381: MLflow authorization bypass in tracing and assessment endpointshighCVSS 7.1EPSS 0.3%
- CVE-2025-14287: MLflow command injection in SageMaker container parameterhighCVSS 8.8EPSS 1.5%
- CVE-2026-2635: MLflow authentication bypass via hard-coded default credentialshighCVSS 7.3EPSS 1.2%
- CVE-2026-2033: MLflow Tracking Server directory traversal remote code executionhighCVSS 7.3EPSS 1.7%
Most severe MLflow vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-64849: MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to…criticalexploited in the wildCVSS 9.3EPSS 9.8%
- CVE-2025-15036: MLflow path traversal in extract_archive_to_dircriticalCVSS 10EPSS 0.6%
- CVE-2026-0545: MLflow authentication bypass in FastAPI job endpointscriticalCVSS 9.8EPSS 4.4%
- CVE-2026-0596: MLflow command injection in model serving via model_uricriticalCVSS 9.6EPSS 1.3%
- CVE-2026-2611: MLflow MLflow Assistant improper origin validation in /ajax-apicriticalCVSS 9.6EPSS 0.4%
- CVE-2026-4035: MLflow AI Gateway credential exfiltration via environment variable resolutioncriticalCVSS 9.1EPSS 0.7%
- CVE-2026-2651: MLflow missing authorization in multipart upload endpointscriticalCVSS 9EPSS 0.5%
- CVE-2025-14287: MLflow command injection in SageMaker container parameterhighCVSS 8.8EPSS 1.5%
- CVE-2026-96804: MLflow statsmodels flavor arbitrary code execution via pickle deserializationhighCVSS 8.8EPSS 0.4%
- CVE-2026-96775: MLflow dspy flavor insufficient pickle deserialization controlhighCVSS 8.8EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 1 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 1 | 1 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 2 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/mlflow.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "MLflow vulnerabilities", https://junglewise.ai/threats/vendors/mlflow, 26 September 2026.