CVE-2026-13484Disclosure(lfprojects / mlflow)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schema CRUD API. Such manipulation leads to missing authorization. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. A reply to the GitHub issue explains, that "[t]he labeling schema PR has not been merged yet. The auth handlers will be added before the release."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mlflow

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
mlflow

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-28: 3Technical Details · 2026-06-28: 106-28
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13484 A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scope… https://www.cve.org/CVERecord?id=CVE-2026-13484 ----- Traducción: CVE-2026-13484 Se … http://infoflow.cloud`

    Post summary

    A newly reported CVE (CVE‑2026‑13484) affecting MLflow is announced with minimal technical details and no evidence of exploitation, patch, or PoC.

    0000037
    89 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-13484 A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scope… https://www.cve.org/CVERecord?id=CVE-2026-13484

    Post summary

    The statement only identifies CVE-2026-13484 in MLflow without providing additional details or actionable information.

    00000708
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-13484 Missing Authorization in MLflow Experiment-Scoped Label Schema CRUD API https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13484

    Post summary

    A new CVE (CVE-2026-13484) is disclosed, highlighting a missing authorization issue in MLflow’s Experiment-Scoped Label Schema CRUD API; no exploit, patch, or active exploitation details are mentioned.

    00000127
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmlflow---

Explore more