CVE-2026-69148Patch

MEDIUMCVSS 7.1 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in mlflow/server/handlers.py verifies only path containment, allowing authenticated users to create a model version that references another user's artifact directory and read files through GET /model-versions/get-artifact without the required READ permission. This issue is fixed in version 3.15.0.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-08-18); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-18: 1Mentions · 2026-08-20: 1Active Exploitation · 2026-08-20: 1Patch / Workaround · 2026-08-18: 1Patch / Workaround · 2026-08-20: 1Technical Details · 2026-08-18: 1Technical Details · 2026-08-20: 108-1808-20
Signal classification2 categories
Patch
150.0%
Active Exploitation
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-181
Patch1
2026-08-201
Active Exploitation1
Full discourse2 posts
  • Checkmarx Zero@CheckmarxZero
    Active Exploitation

    🚨 If you're running MLflow, stop and read this. CVE-2026-64849 is a critical unauthenticated SSRF discovered in the default MLflow Tracking server. It lets attackers reach internal services and potentially steal sensitive data without requiring a login, and it's already being exploited in the wild. We recommend upgrading to version 3.15.0 as it also fixes two additional flaws affecting MLflow, CVE-2026-69148 and CVE-2026-69146. More details: https://devhub.checkmarx.com/cve-details/CVE-2026-64849/

    Post summary

    CVE-2026‑64849 is a critical unauthenticated SSRF in MLflow, actively exploited in the wild; updating to 3.15.0 resolves the issue.

    0002091
    247 followersView on X
  • iSECTECH@isectech_
    Patch

    MLflow CVE-2026-69148 lets an authenticated user reference another user’s run and read its artifacts in affected deployments. Upgrade to 3.15.0 and hunt model versions whose sources cross ownership boundaries. https://github.com/mlflow/mlflow/security/advisories/GHSA-gqch-g4w5-7qcw

    Post summary

    The advisory reveals that CVE‑2026‑69148 enables authenticated users to read other users’ run artifacts and recommends upgrading MLflow to version 3.15.0 to address the issue.

    0000032
    86 followersView on X

Explore more