Webhook Validation Flaw in MLflow Affects Data Integrity
CVE-2026-64849

9.3CRITICAL

Key Information:

Vendor

Mlflow

Status
Vendor
CVE Published:
17 August 2026

Badges

📈 Trended📈 Score: 2,840👾 Exploit Exists🟡 Public PoC🟣 EPSS 16%🦅 CISA Reported📰 News Worthy

What is CVE-2026-64849?

CVE-2026-64849 is a vulnerability found in MLflow, an open-source platform designed for managing the end-to-end machine learning lifecycle. This includes functionalities such as tracking experiments, packaging code into reproducible runs, and sharing and deploying models. The vulnerability arises from a flaw in the webhook validation process where the unauthenticated endpoint for testing webhooks improperly handles URL validation. Specifically, it only checks the original URL without ensuring that redirects are validated, allowing potential attackers to access sensitive internal or cloud-based metadata services. This oversight could lead to unauthorized information disclosure, compromising the integrity and confidentiality of data handled by organizations utilizing MLflow.

Potential impact of CVE-2026-64849

  1. Data Exposure: The vulnerability could allow attackers to reach internal or cloud metadata services, leading to unauthorized access to sensitive data. This risk increases the potential for data leaks and violations of data protection regulations.

  2. Integrity Compromise: By enabling unauthorized access to critical services, the vulnerability jeopardizes the integrity of data processed within the MLflow platform. Attackers could manipulate or corrupt data, leading to unreliable machine learning outcomes and business decisions.

  3. Operational Disruption: Exploiting this vulnerability could result in operational disruptions as attackers might leverage unauthorized access to interfere with ongoing machine learning processes, potentially affecting the reliability and performance of AI-driven applications critical to business operations.

CISA has reported CVE-2026-64849

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-64849 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

mlflow < 3.15.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

CISA warns of hackers exploiting critical MLflow vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform.

3 weeks ago

MLflow Vulnerability Exploited for Cloud Credential Theft

Hackers are exploiting CVE-2026-64849, a critical SSRF vulnerability in MLflow, to steal credentials and secrets.

3 weeks ago

References

EPSS Score

16% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 🟡

    Public PoC available

  • 📰

    First article discovered by Securityweek

  • 📈

    Vulnerability started trending

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • Vulnerability published

  • Vulnerability Reserved

.