Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

MLflow multiple vulnerabilities in versions prior to 3.15.0

Three vulnerabilities were identified in MLflow prior to version 3.15.0, including an unauthenticated SSRF via webhook validation bypass, an authentication bypass allowing injection of dataset metadata, and a path traversal enabling unauthorized artifact access. All issues were fixed in version 3.15.0.

Disclosed 17 August 2026 · Record updated 13 September 2026

Impact

Authenticated users could inject malicious metadata into other users' runs, read unauthorized artifacts, and unauthenticated users could access internal metadata services through webhook validation bypass.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-64849
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-69146
  3. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-69148