CVE-2026-2611Patch(lfprojects / mlflow)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch lfprojects mlflow systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cross-origin requests from a malicious webpage to interact with the MLflow Assistant running on a victim's local machine. By bypassing the loopback-only restriction, the attacker can modify the Assistant's configuration to enable full access, which in turn allows the execution of arbitrary commands via the Claude Code sub-agent. This issue is resolved in version 3.10.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346CWE-940

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mlflow

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-19); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
mlflow

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-19: 1Mentions · 2026-05-24: 1Patch / Workaround · 2026-05-19: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-24: 105-1905-24
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-191
Patch1
2026-05-241
Disclosure1
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - MLflow Assistant Origin Validation Bypass Leads to RCE (CVE-2026-2611) MLflow Assistant contains an improper origin validation vulnerability in /ajax-api endpoints that allows malicious websites to interact with a locally running MLflow instance. Successful exploitation may let attackers modify Assistant settings and execute arbitrary commands through the Claude Code sub-agent. 👉 Affected: MLflow 3.9.0 | Fix: Upgrade to MLflow 3.10.0 immediately

    Post summary

    The post announces CVE-2026-2611, a RCE vulnerability caused by improper origin validation in MLflow Assistant, and urges an immediate upgrade to version 3.10.0.

    00020122
    255 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 MLflow, Improper Origin Validation, #CVE-2026-2611 (Critical) https://dailycve.com/mlflow-improper-origin-validation-cve-2026-2611-critical/

    Post summary

    The text announces the critical CVE-2026-2611 affecting MLflow, noting an improper origin validation issue. It references a dailycve.com article for further details.

    0000058
    207 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmlflow---

Explore more