
[ZDI-26-105|CVE-2026-2033] MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability (CVSS 8.1; Credit: Muhammad Fadilullah Dzaki) https://www.zerodayinitiative.com/advisories/ZDI-26-105/
Post summary
The advisory announces a directory traversal Remote Code Execution flaw (CVE‑2026‑2033) in MLflow Tracking Server with a CVSS score of 8.1, crediting the discoverer, but does not mention active exploitation, patches, or a PoC.

