Code Execution Risk in MLflow Platform by Hidden Layer
CVE-2026-79721

8.6HIGH

Key Information:

Vendor

Mlflow

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-79721?

The MLflow platform allows for the execution of arbitrary code through crafted model artifacts. Versions from 0.0.1 onward are at risk, as a malicious actor can exploit this vulnerability by loading a compromised model, leading to serious security concerns for end users.

Affected Version(s)

mlflow 0.0.1

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.