CVE-2026-2635Disclosure

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the basic_auth.ini file. The file contains hard-coded default credentials. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of the administrator. Was ZDI-CAN-28256.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1393CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 1 mentions (2026-02-19); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-19: 1Mentions · 2026-02-20: 1Mentions · 2026-02-23: 1Mentions · 2026-03-18: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-20: 1Technical Details · 2026-02-23: 1Technical Details · 2026-03-18: 102-1902-2002-2303-18
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-191
Disclosure1
2026-02-201
Disclosure1
2026-02-231
Disclosure1
2026-03-181
Patch1
Full discourse4 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-111|CVE-2026-2635] MLflow Use of Default Password Authentication Bypass Vulnerability (CVSS 9.8; Credit: Peter Girnus (@gothburz) of Trend Zero Day Initiative) https://www.zerodayinitiative.com/advisories/ZDI-26-111/

    Post summary

    The advisory announces CVE-2026-2635, a high-severity authentication bypass in MLflow due to use of default passwords, with a CVSS score of 9.8.

    100531.2K
    5.3K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    An authentication bypass vulnerability (CVE-2026-2635) affects `MLflow` due to default passwords. Review configurations and enforce strong credentials to prevent unauthorized access. #MLflow #AuthBypass #infosec https://www.pulsepatch.io/posts/cve-2026-2635-mlflow-default-password-bypass

    Post summary

    CVE-2026-2635 is an authentication bypass in MLflow caused by default passwords; remediation involves updating configuration to enforce strong credentials.

    0000031
    1 followersView on X
  • The AI generalist@AIengineerlife
    Disclosure

    🚨 CVE-2026-2635 - CRITICAL MLflow 🤖 AI Summary: Critical auth bypass in MLflow via hard-coded default credentials. Allows remote code execution with admin privileges. ThreatScore: 85/100 🔗 http://threatmonitor.io/cve/CVE-2026-2635 #cybersecurity #infosec #CVE

    Post summary

    The post announces a critical authentication bypass in MLflow (CVE‑2026‑2635) that permits remote code execution through hard‑coded default credentials, but it does not provide a PoC, exploit, or patch information.

    0000052
    7 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2635 MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLf… https://www.cve.org/CVERecord?id=CVE-2026-2635

    Post summary

    CVE‑2026‑2635 identifies an authentication bypass in MLflow due to default passwords allowing remote attackers to gain unauthorized access; no exploit, PoC, or patch details are provided.

    0000074
    56.4K followersView on X

Explore more