Critical MLflow SSRF Flaw Lets Attackers Steal Cloud IAM Credentials Without Login
A critical unauthenticated server-side request forgery (SSRF) vulnerability, CVE-2026-64849, has been disclosed in MLflow Tracking Server versions 3.14.0 and earlier, with a security advisory published on August 19, 2026. The flaw allows external attackers to create webhooks via an unauthenticated API and redirect MLflow into fetching cloud metadata endpoints, such as AWS EC2 instance metadata, exposing temporary IAM credentials. MLflow fails to re-validate redirect destinations, meaning a 302 redirect from an attacker-controlled server to internal or link-local addresses bypasses protection checks entirely. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Users are advised to upgrade to MLflow 3.15.0 or later and restrict public access to the tracking server using authenticated reverse proxies and least-privilege IAM roles.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in