VulnWatch VulnWatch
← Back to dashboard
Low osv · PYSEC-2026-415

MLflow authentication requirement bypass can allow a user to arbitrarily create an account

Published Jun 29, 2026 CVSS 3.0

An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirement.

Affected AI Products

mlflow
Get the weekly digest. Every Monday: top AI security stories of the week. Free.