CVE-2026-2652Disclosure(lfprojects / mlflow)

LOWCVSS 8.6 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for lfprojects mlflow systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) and served via uvicorn (ASGI). The FastAPI permission middleware only enforces authentication on `/gateway/` routes, leaving other routes such as the Job API (`/ajax-api/3.0/jobs/*`) and the OpenTelemetry trace ingestion API (`/v1/traces`) unprotected. This allows unauthenticated remote attackers to submit jobs, read job results, cancel running jobs, and inject arbitrary trace data into experiments. The issue arises from an architectural mismatch between Flask and FastAPI authentication mechanisms, where the `_find_fastapi_validator()` function fails to handle non-`/gateway/` paths, resulting in a complete authentication bypass. This vulnerability is fixed in version 3.10.0.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-305

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mlflow

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-19); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
mlflow

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-19: 1Mentions · 2026-08-10: 1Active Exploitation · 2026-08-10: 1Technical Details · 2026-05-19: 1Technical Details · 2026-08-10: 105-1908-10
Signal classification2 categories
Disclosure
150.0%
Active Exploitation
150.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-191
Disclosure1
2026-08-101
Active Exploitation1
Full discourse2 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-2652 (CVSS 8.6): Unauthenticated access to some FastAPI routes when basic-auth is enabled under uvicorn 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJNTGZsb3ci 🎯9.7K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="MLflow" 🔖Refer: https://huntr.com/bounties/5aeff5f0-49c7-4180-b5cb-c9a046f16756 #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post announces CVE‑2026‑2652, describing an unauthenticated access flaw in FastAPI routes under uvicorn, and shares FOFA search results and a bounty link without providing PoC or exploit details.

    010034172.8K
    14.4K followersView on X
  • CrowdSec@Crowd_Security
    Active Exploitation

    🚨 In this week’s newsletter, we cover CVE-2026-2652, an authentication bypass vulnerability affecting MLflow that is seeing active exploitation. We break down how attackers can access protected API endpoints without credentials, potentially exposing jobs and connected infrastructure, and what defenders should do next. Read the full analysis and protect your systems 👉 https://www.crowdsec.net/vulntracking-report/cve-2026-2652-mlflow-authentication-bypass

    Post summary

    The post announces that CVE-2026-2652 is an authentication bypass in MLflow, currently being exploited in the wild, without providing a PoC, exploit code, or patch details.

    00030498
    19.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfprojectsmlflow---

Explore more