Feed/CVE-2026-2651
CVE-2026-2651CRITICALCVSS 9.0

MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled

Published May 26, 2026·Updated Jul 21, 2026

NVD Description

A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permission checks for `/mlflow-artifacts/mpu/*` endpoints, enabling attackers to overwrite artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue is resolved in version 3.10.0.

Affected Packages (1)

mlflowPYPI
Fixed in 3.11.0rc0

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free