CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-2651

Critical · CVSS 9.0

MLflow — Missing Authorization / Improper Authorization on Multipart Upload Endpoints (CWE-862, CWE-1220)

CVSS
9.0
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-862, CWE-1220

Description

A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permission checks for `/mlflow-artifacts/mpu/*` endpoints, enabling attackers to overwrite artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue is resolved in version 3.10.0.

Search profile — drives PoC discovery

Symbols /mlflow-artifacts/mpu/*--serve-artifactsmultipart uploadMPUmlflow-artifactsserve_artifactsmpu_endpointsauthorizationresource-level permission
Keywords CVE-2026-2651MLflow multipart upload unauthorized accessMLflow MPU endpoint missing authorizationMLflow serve-artifacts bypassMLflow artifact overwriteMLflow model supply chain poisoningMLflow mpu PoCMLflow CWE-862MLflow unauthorized cross-user writeMLflow 3.10.0 patch
Versions: <=3.10.1.dev0

Affected packages

Bitnami mlflow 0 → 3.11.1
PyPI mlflow 0 → 3.11.0rc0
PyPI mlflow 0 → 3.11.0rc1

References

Status: enriched · ingested 2026-06-27T06:00:38.000Z · profiled 2026-07-01T00:30:14.000Z