Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2026-2651

2 месяца назад

A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permission checks for `/mlflow-artifacts/mpu/*` endpoints, enabling attackers to overwrite artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue is resolved in version 3.10.0.

CVSS3: 9
EPSS: Низкий
nvd логотип

CVE-2026-2651

2 месяца назад

A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permission checks for `/mlflow-artifacts/mpu/*` endpoints, enabling attackers to overwrite artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue is resolved in version 3.10.0.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-8c7q-86fq-vvmh

2 месяца назад

MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled

CVSS3: 9
EPSS: Низкий
fstec логотип

BDU:2026-07859

6 месяцев назад

Уязвимость платформы управления жизненным циклом моделей машинного обучения MLflow, связанная с недостатками процедуры авторизации, позволяющая нарушителю выполнить произвольный код

CVSS3: 9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-2651

A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permission checks for `/mlflow-artifacts/mpu/*` endpoints, enabling attackers to overwrite artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue is resolved in version 3.10.0.

CVSS3: 9
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-2651

A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permission checks for `/mlflow-artifacts/mpu/*` endpoints, enabling attackers to overwrite artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue is resolved in version 3.10.0.

CVSS3: 9
0%
Низкий
2 месяца назад
github логотип
GHSA-8c7q-86fq-vvmh

MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled

CVSS3: 9
0%
Низкий
2 месяца назад
fstec логотип
BDU:2026-07859

Уязвимость платформы управления жизненным циклом моделей машинного обучения MLflow, связанная с недостатками процедуры авторизации, позволяющая нарушителю выполнить произвольный код

CVSS3: 9
0%
Низкий
6 месяцев назад

Уязвимостей на страницу