Low
osv
·
PYSEC-2026-94
PYSEC-2026-94
Published Apr 7, 2026
CVSS 3.1
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access‑control validation, a user without permissions to a given experiment can directly query this endpoint and retrieve model artifacts they are not authorized to access.
This issue affects MLflow version through 3.10.1
Affected AI Products
mlflow