CVE-2026-0596Disclosure(lfprojects / mlflow)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch lfprojects mlflow systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into a shell command executed via `bash -c` without proper sanitization. If the `model_uri` contains shell metacharacters, such as `$()` or backticks, it allows for command substitution and execution of attacker-controlled commands. This vulnerability affects the latest version of mlflow/mlflow and can lead to privilege escalation if a higher-privileged service serves models from a directory writable by lower-privileged users.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mlflow

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 5 mentions (2026-03-31); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
mlflow

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-03-31: 5Mentions · 2026-04-01: 1Mentions · 2026-04-04: 1Patch / Workaround · 2026-04-04: 1Technical Details · 2026-03-31: 5Technical Details · 2026-04-01: 1Technical Details · 2026-04-04: 103-3104-0104-04
Signal classification2 categories
Disclosure
685.7%
General
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-315
Disclosure4General1
2026-04-011
Disclosure1
2026-04-041
Disclosure1
Full discourse7 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-0596: CRITICAL] Vulnerability in mlflow when serving models with `enable_mlserver=True` allows command injections. Attackers can execute code via shell metacharacters, affecting latest versions & ris...#cve,CVE-2026-0596,#cybersecurity https://cvefind.com/CVE-2026-0596

    Post summary

    The tweet announces a critical command‑injection vulnerability in mlflow (enable_mlserver=True) without providing PoC, exploit code, or patch information.

    0001039
    617 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0596 A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into a shell command ex… https://www.cve.org/CVERecord?id=CVE-2026-0596

    Post summary

    The text announces CVE-2026-0596, a command injection flaw in mlflow/mlflow during model serving, detailing the root cause but offering no PoC, exploit, or remediation information.

    0001071
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-0596: Command Injection in mlflow/mlflo... MLflow's `enable_mlserver=True` flag turns your model serving into a shell injection playground - `model_uri` gets bash-... https://zerodaysignal.com/vulnerability/CVE-2026-0596 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑0596, describing a command injection flaw in MLflow’s enable_mlserver flag that can lead to shell injection.

    0001050
    194 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A command injection vulnerability affects `Mflow` when `enable_mlserver=True` (CVE-2026-0596). This could lead to remote code execution. Review configurations. #infosec #security https://www.pulsepatch.io/posts/cve-2026-0596-mflow-command-injection

    Post summary

    The post announces a command‑injection flaw (CVE‑2026‑0596) in Mflow that can enable remote code execution, and advises reviewing configurations as a mitigation.

    0000065
    11 followersView on X
  • CosmicBytez@CosmicBytez
    Disclosure

    Security Advisory: CVE-2026-0596: MLflow Command Injection via Unsanitized model_uri (CVSS 9.6) https://labs.cosmicbytez.ca/security/cve-2026-0596 #Cybersecurity #InfoSec #CVE #PatchNow

    Post summary

    The advisory announces a critical (CVSS 9.6) command injection flaw in MLflow (CVE-2026-0596) caused by unsanitized model_uri inputs, but does not provide PoC, exploit code, or patch details.

    0000037
    1 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-0596 - Critical A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into a shell command executed via `bash -c`... https://www.thehackerwire.com/vulnerability/CVE-2026-0596/ https://t.co/dfCWThbCXj

    Post summary

    A new command injection vulnerability (CVE‑2026‑0596) affecting mlflow’s model serving with enable_mlserver=True has been disclosed, with technical details and a reference link.

    0000040
    163 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-0596 - Command Injection in mlflow/mlflow Intel Report: https://ift.tt/jQpD9fO

    Post summary

    The alert announces CVE‑2026‑0596, a command‑injection flaw in mlflow/mlflow, with an intel report link but no PoC, exploit tool, active exploitation, or patch details.

    0000036
    281 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmlflow---

Explore more