Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 22, 2026 (about 3 months ago).

people · May 22, 2026

CVE-2026-0545 Authentication Bypass Vulnerability Reported in MLflow

Share the canonical public link.

Share as image

A critical authentication bypass vulnerability designated CVE-2026-0545 was identified in MLflow versions prior to certain patches. The flaw affects FastAPI job endpoints under /ajax-api/3.0/jobs/* allowing unauthenticated access even when basic-auth is enabled. It potentially enables remote code execution, job submission, or denial-of-service attacks on unpatched installations. The issue was disclosed via huntr.dev with references to MLflow 3.9.0 in related reports.

Below validation threshold — auto-passed without scoring

Supporting evidence