Deserialization Vulnerability in FedML-AI's MQTT+S3 Communication Backend
CVE-2026-90614

5.3MEDIUM

Key Information:

Vendor

Fedml-ai

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-90614?

A deserialization vulnerability has been identified in the MQTT+S3 Communication Backend of FedML-AI. Specifically, the issue arises in the S3Storage.read_model function located in remote_storage.py. Manipulation of the s3_key_str argument enables remote attackers to exploit this vulnerability, potentially leading to unauthorized access and actions within the affected systems. Despite being reported to the project, there has been no response or remediation action from the developers.

Affected Version(s)

FedML 0.9.0

FedML 0.9.1

FedML 0.9.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mohammedix88 (VulDB User)
VulDB CNA Team
.