MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access‑control validation, a user without permissions to a given experiment can directly query this endpoint and retrieve model artifacts they are not authorized to access.
This issue affects MLflow version through 3.10.1
References
| Link | Resource |
|---|---|
| https://afine.com/blogs/attacking-mlflow-how-ml-artifacts-become-attack-vectors | Exploit Third Party Advisory |
| https://cert.pl/en/posts/2026/04/CVE-2026-33865/ | Third Party Advisory |
| https://github.com/mlflow/mlflow/pull/21708 | Issue Tracking Patch |
Configurations
History
No history.
Information
Published : 2026-04-07 13:16
Updated : 2026-06-17 10:38
NVD link : CVE-2026-33866
Mitre link : CVE-2026-33866
CVE.ORG link : CVE-2026-33866
JSON object : View
Products Affected
lfprojects
- mlflow
CWE
CWE-862
Missing Authorization
