
🚨 Critical - MLflow Missing Authorization → Model Supply Chain Poisoning (CVE-2026-2651) A missing authorization check on the /mlflow-artifacts/mpu/* endpoints allows any authenticated user to overwrite artifacts belonging to other users when --serve-artifacts mode is enabled. An attacker can silently replace a legitimate model with a malicious one, leading to arbitrary code execution when the compromised artifact is loaded downstream (CVSS 9.0). 👉 Affected: mlflow (pip) ≤ 3.10.1.dev0 with --serve-artifacts enabled | Upgrade to 3.10.0
Post summary
A critical CVE-2026-2651 in MLflow allows authenticated users to overwrite artifacts and execute arbitrary code; upgrading to 3.10.0 removes the vulnerability.

