afine.comexploitTechnical description
https://afine.com/blogs/attacking-mlflow-how-ml-artifacts-become-attack-vectors CVE-2026-33866
MEDIUM
Authorization Bypass in MLflow AJAX Endpoint
Record summary
CVE-2026-33866 has a selected CVSS score of 5.3 (medium).
Description
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access‑control validation, a user without permissions to a given experiment can directly query this endpoint and retrieve model artifacts they are not authorized to access. This issue affects MLflow version through 3.10.1
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 14, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
MlflowBrowse Mlflow / MlflowDefault status: unaffected | CVE List | Through 3.10.1 | affected |
mlflowBrowse PyPI / mlflow | GitHub Advisory | Before 3.11.0rc0 · Fixed in 3.11.0rc0 | affected |
References
7cert.plThird-party advisory
https://cert.pl/en/posts/2026/04/CVE-2026-33865 github.com
https://github.com/mlflow/mlflow github.com
https://github.com/mlflow/mlflow/commit/005b959cacda05d1423356cfcbd9ebeda8ff96a7 github.compatch
https://github.com/mlflow/mlflow/pull/21708 github.com
https://github.com/pypa/advisory-database/tree/main/vulns/mlflow/PYSEC-2026-94.yaml nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-33866