people · May 22, 2026
CVE-2026-0545 Authentication Bypass Vulnerability Reported in MLflow
Share the canonical public link.
A critical authentication bypass vulnerability designated CVE-2026-0545 was identified in MLflow versions prior to certain patches. The flaw affects FastAPI job endpoints under /ajax-api/3.0/jobs/* allowing unauthenticated access even when basic-auth is enabled. It potentially enables remote code execution, job submission, or denial-of-service attacks on unpatched installations. The issue was disclosed via huntr.dev with references to MLflow 3.9.0 in related reports.
Below validation threshold — auto-passed without scoring