CVE-2026-0545Disclosure(lfprojects / mlflow)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch lfprojects mlflow systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled (`MLFLOW_SERVER_ENABLE_JOB_EXECUTION=true`) and any job function is allowlisted, any network client can submit, read, search, and cancel jobs without credentials, bypassing basic-auth entirely. This can lead to unauthenticated remote code execution if allowed jobs perform privileged actions such as shell execution or filesystem changes. Even if jobs are deemed safe, this still constitutes an authentication bypass, potentially resulting in job spam, denial of service (DoS), or data exposure in job results.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mlflow

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 4 mentions (2026-04-03); latest day: 2
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
mlflow

1 version affected across 1 product

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-04-03: 4Mentions · 2026-04-04: 1Mentions · 2026-04-08: 1Mentions · 2026-05-05: 1Mentions · 2026-08-28: 2PoC Mentioned / Linked · 2026-05-05: 1PoC Mentioned / Linked · 2026-08-28: 1Exploit Tool / Code · 2026-08-28: 1Patch / Workaround · 2026-08-28: 2Technical Details · 2026-04-03: 4Technical Details · 2026-04-04: 1Technical Details · 2026-04-08: 1Technical Details · 2026-05-05: 1Technical Details · 2026-08-28: 204-0304-0404-0805-0508-28
Signal classification3 categories
Disclosure
777.8%
General
111.1%
Patch
111.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-034
Disclosure3General1
2026-04-041
Disclosure1
2026-04-081
Disclosure1
2026-05-051
Disclosure1
2026-08-282
Disclosure1Patch1
Full discourse9 posts
  • ThreatWire@ThreatWire_
    Patch

    🚨 CRITICAL: CVE-2026-0545 is an authentication bypass in MLflow that exposes its Job API even when Basic Auth is enabled. An unauthenticated attacker can submit and control parameters for registered jobs through /ajax-api/3.0/jobs/*. If job execution is enabled, the impact can escalate to remote code execution, depending on the functions allowed by the server. 🔴 MLflow ≤ 3.10.1 is affected. Patch immediately. 🔗 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-0545.yaml #MLflow #CVE #RCE #AuthenticationBypass #AI #CyberSecurity #Infosec

    Post summary

    CVE‑2026‑0545 is a critical authentication bypass in MLflow that can lead to remote code execution when job execution is enabled; versions up to 3.10.1 are affected and should be patched immediately.

    25029102.2K
    1.7K followersView on X
  • dbugs@ptdbugs
    Disclosure

    CVE-2026-0545: MLflow's basic-auth Only Gated Flask An analysis of CVE-2026-0545 has been published — an authentication bypass in MLflow that emerged during the server's migration from Flask to FastAPI. When Basic Auth was enabled, some APIs remained accessible without credentials. MLflow uses a hybrid architecture: several native routes are handled directly by FastAPI, while the entire Flask application is mounted at "/" via WSGI. The two authentication gates have opposite defaults: Flask → deny by default FastAPI → allow by default The FastAPI middleware checked only routes for which a validator had been registered. If no validator was found, the request was simply forwarded without authentication. As a result, three of the four FastAPI routers were publicly accessible without authentication: "/v1/traces" "/ajax-api/3.0/jobs" "/ajax-api/3.0/mlflow/assistant" CVE-2026-0545 CVE-2026-0545 covers the authentication bypass on "POST /ajax-api/3.0/jobs/". The endpoint allows clients to launch jobs registered on the server and pass parameters to them. An arbitrary function cannot be selected — the available jobs are limited to an internal list of supported functions. However, an unauthenticated attacker could launch any registered job with attacker-controlled parameters. The impact depends on the registered functions: from running judge-LLM jobs against the operator's billing account to potential remote code execution. Exploitation requires the job runner to be enabled through" MLFLOW_SERVER_ENABLE_JOB_EXECUTION". The patch fixed the vulnerability, but not the underlying architectural issue The fix added the three missing FastAPI prefixes to the validator lookup: "/jobs" and "/assistant" now require authentication, while "/v1/traces" received a separate authorization check. The author calls this class of bugs a Parallel Implementation Gap: a single security policy is implemented independently across multiple components, and their behavior diverges over time. In MLflow, the list of FastAPI routers and the list of validators protecting them are located in different files and must be kept synchronized manually. The architectural risk therefore remains: Flask requires authentication by default, while FastAPI forwards unmatched routes without authentication. A new router for which a developer forgets to register a validator could once again end up publicly accessible without authentication. PoC (Nuclei template): https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-0545.yaml Article: https://nefariousplan.com/posts/mlflow-basic-auth-only-gated-flask #dbugs_attacks

    Post summary

    The article discloses an authentication bypass in MLflow, provides a PoC and patch details, but does not report active exploitation.

    30012884
    3.3K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-0545 - critical 🚨 MLflow Job API - Authentication Bypass > MLflow latest version contains an authentication bypass caused by unprotected FastAPI... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-0545 @pdnuclei #NucleiTemplates #cve

    Post summary

    The text announces CVE‑2026‑0545, an authentication bypass in MLflow’s Job API, and shares a detection template link, but does not provide exploitation code, active usage data, or a patch.

    00013204
    944 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Unauthenticated access to `mlflow` FastAPI job endpoints (CVE-2026-0545) allows unauthorized operations. Assess exposure and implement access controls. #mlflow #security #APISecurity https://www.pulsepatch.io/posts/cve-2026-0545-mlflow-unauthenticated-job-endpoints

    Post summary

    The tweet announces CVE‑2026‑0545, noting that unauthenticated access to mlflow FastAPI job endpoints allows unauthorized operations, and urges assessment and access‑control implementation.

    0000031
    11 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-0545 - Critical In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affec... https://www.thehackerwire.com/vulnerability/CVE-2026-0545/ https://t.co/WfdmeeBUAw

    Post summary

    The post announces the CVE‑2026‑0545 vulnerability in mlflow, detailing a lack of authentication on certain endpoints, but does not provide a PoC, patch, or evidence of active exploitation.

    0000064
    164 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-0545 - Missing Authentication for Critical Function in mlflow/mlflow Intel Report: https://ift.tt/L4FG2dO

    Post summary

    The alert references CVE-2026-0545 as a missing authentication flaw in mlflow, but provides no PoC, exploit, patch, or active exploitation details.

    0000062
    281 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-0545: CRITICAL] Vulnerability alert in mlflow/mlflow: Unauthenticated access to FastAPI job endpoints under `/ajax-api/3.0/jobs/*` even with `basic-auth` enabled, posing risk of remote code execution.#cve,CVE-2026-0545,#cybersecurity https://cvefind.com/CVE-2026-0545

    Post summary

    An alert about CVE-2026-0545 describes unauthenticated access to mlflow job endpoints that could lead to remote code execution, with no evidence of active exploitation, published PoC, or available patch.

    0000065
    617 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0545 In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This… https://www.cve.org/CVERecord?id=CVE-2026-0545

    Post summary

    The text discloses a new CVE (CVE-2026-0545) in the MLflow project, indicating that job endpoints lack authentication when basic-auth is enabled.

    00000122
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-0545: Missing Authentication for Critic... MLflow's FastAPI job endpoints completely bypass basic-auth - unauthenticated RCE if job execution enabled, guaranteed D... https://zerodaysignal.com/vulnerability/CVE-2026-0545 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A missing authentication flaw in MLflow's FastAPI job endpoints permits unauthenticated remote code execution when job execution is enabled, representing a severe vulnerability.

    0000066
    197 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmlflow---

Explore more