CVE-2026-96804

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-24: 109-24
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨High - MLflow Pickle Deserialization RCE (CVE-2026-96804, CVE-2026-96775) MLflow’s statsmodels and dspy flavors bypass MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False. Crafted MLmodel artifacts can trigger unsafe pickle deserialization and execute arbitrary code when loaded. Deployments that never load untrusted model artifacts are not exposed. 👉Affected: MLflow statsmodels 2.1.0-3.14.0 | Upgrade to 3.15.0; MLflow dspy >=2.0 | Avoid loading untrusted dspy artifacts until a fix is available

    0000024
    305 followersView on X

Explore more