This issue affects MLflow version through 3.10.1
Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access‑control validation, a user without permissions to a given experiment can directly query this endpoint and retrieve model artifacts they are not authorized to access. This issue affects MLflow version through 3.10.1 | |
| Title | Authorization Bypass in MLflow AJAX Endpoint | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-04-07T13:05:47.658Z
Reserved: 2026-03-24T13:13:32.905Z
Link: CVE-2026-33866
Updated: 2026-04-07T13:05:41.111Z
Status : Awaiting Analysis
Published: 2026-04-07T13:16:47.000
Modified: 2026-04-07T13:20:11.643
Link: CVE-2026-33866
No data.
OpenCVE Enrichment
No data.