CVE-2026-2611

CRITICAL

Improper Origin Validation in mlflow/mlflow

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-2611. PoCs published by fearlessresponsesolution.

AI-analyzed exploit summary The repository contains decompiled C# code from a Windows patch (KB5002834), likely related to a .NET or Office vulnerability. The files include RTTI (Run-Time Type Information) structures, exception handling, and memory management artifacts, suggesting a deep dive into the patched binary's internals.

Description

In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cross-origin requests from a malicious webpage to interact with the MLflow Assistant running on a victim's local machine. By bypassing the loopback-only restriction, the attacker can modify the Assistant's configuration to enable full access, which in turn allows the execution of arbitrary commands via the Claude Code sub-agent. This issue is resolved in version 3.10.0.

Exploits (1)

github WRITEUP
by fearlessresponsesolution · tsqlpoc
https://github.com/fearlessresponsesolution/cve-pocs/tree/master/pocs/CVE-2026-2611

The repository contains decompiled C# code from a Windows patch (KB5002834), likely related to a .NET or Office vulnerability. The files include RTTI (Run-Time Type Information) structures, exception handling, and memory management artifacts, suggesting a deep dive into the patched binary's internals.

Classification
Writeup 80%
Attack Type
Other
Complexity
Complex
Reliability
Theoretical
Target: Microsoft .NET Framework or Office (KB5002834)
No auth needed
Prerequisites: Access to the patched binary (KB5002834) · Decompilation tools
devstral-2 · analyzed May 19, 2026 Full analysis →

Scores

CVSS v3 9.6
EPSS 0.0004
EPSS Percentile 11.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-346
Status published
Products (3)
lfprojects/mlflow 3.9.0 - 3.10.0
mlflow/mlflow/mlflow unspecified - 3.10.0
pypi/mlflow 3.9.0 - 3.10.0PyPI
Published May 19, 2026
Tracked Since May 19, 2026