CVE-2026-2614
published 2026-05-11CVE-2026-2614: A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated…
PriorityP180high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
3.21%
87.7th percentile
A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem. The issue arises when a `CreateModelVersion` request includes the tag `mlflow.prompt.is_prompt`, which bypasses source path validation. This enables an attacker to store an arbitrary local filesystem path as the model version source. The `get_model_version_artifact_handler()` function later uses this source to serve files without verifying the model version's prompt status, leading to a complete confidentiality compromise. This issue is fixed in version 3.10.0.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lfprojects | mlflow | < 3.10.0 | 3.10.0 |
| mlflow | mlflow_mlflow | >= 0 < 3.10.0 | 3.10.0 |
| mlflow | mlflow_mlflow | >= unspecified < 3.10.0 | 3.10.0 |
| rhoai | odh-mlflow-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-rocm-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-tensorflow-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-tensorflow-rocm-py312-rhel9 | — | — |
| rhoai | odh-th06-cpu-torch210-py312-rhel9 | — | — |
| rhoai | odh-th06-cuda130-torch210-py312-rhel9 | — | — |
| rhoai | odh-th06-rocm64-torch291-py312-rhel9 | — | — |
| rhoai | odh-training-cuda128-torch29-py312-rhel9 | — | — |
| rhoai | odh-workbench-codeserver-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-rocm-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-tensorflow-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-tensorflow-rocm-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-trustyai-cpu-py312-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vulncheck7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mlflow: mlflow: Arbitrary file read via bypassed source path validation
vendor_redhat·2026-05-11·CVSS 7.5
CVE-2026-2614 [HIGH] CWE-22 mlflow: mlflow: Arbitrary file read via bypassed source path validation
mlflow: mlflow: Arbitrary file read via bypassed source path validation
A flaw was found in mlflow. An unauthenticated remote attacker can exploit a vulnerability in the `_create_model_version()` handler by including a specific tag, `mlflow.prompt.is_prompt`, in a `CreateModelVersion` request. This bypasses source path validation, allowing the attacker to specify an arbitrary local filesystem path as the model version source. Subsequently, the `get_model_version_artifact_handler()` function serves files from this unverified source, leading to the disclosure of arbitrary files from the server's filesystem and a complete confidentiality compromise.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security crite
GHSA
MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
ghsa·2026-05-11
CVE-2026-2614 [HIGH] CWE-22 MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem. The issue arises when a `CreateModelVersion` request includes the tag `mlflow.prompt.is_prompt`, which bypasses source path validation. This enables an attacker to store an arbitrary local filesystem path as the model version source. The `get_model_version_artifact_handler()` function later uses this source to serve files without verifying the model version's prompt status, leading to a complete confidentiality compromise. This issue is fixed in version 3.10.0.
GHSA
GHSA-42h5-h8qh-vv9v: A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers
ghsa_unreviewed·2026-05-11
CVE-2026-2614 [HIGH] CWE-22 GHSA-42h5-h8qh-vv9v: A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers
A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem. The issue arises when a `CreateModelVersion` request includes the tag `mlflow.prompt.is_prompt`, which bypasses source path validation. This enables an attacker to store an arbitrary local filesystem path as the model version source. The `get_model_version_artifact_handler()` function later uses this source to serve files without verifying the model version's prompt status, leading to a complete confidentiality compromise. This issue is fixed in version 3.10.0.
VulnCheck
lfprojects mlflow Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulncheck·2026·CVSS 7.5
CVE-2026-2614 [HIGH] lfprojects mlflow Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
lfprojects mlflow Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem. The issue arises when a `CreateModelVersion` request includes the tag `mlflow.prompt.is_prompt`, which bypasses source path validation. This enables an attacker to store an arbitrary local filesystem path as the model version source. The `get_model_version_artifact_handler()` function later uses this source to serve files without verifying the model version's prompt status, leading to a complete confidentiality compromise. This issue is fixed in version 3.10.0.
Affecte
No detection rules found.
Nuclei
MLflow <= 3.9.0 - Arbitrary File Read
nuclei·CVSS 7.5
CVE-2026-2614 [HIGH] MLflow <= 3.9.0 - Arbitrary File Read
MLflow <= 3.9.0 - Arbitrary File Read
mlflow mlflow <= 3.9.0 contains a path traversal caused by bypassing source path validation via the mlflow.prompt.is_prompt tag in CreateModelVersion request, letting unauthenticated remote attackers read arbitrary files.
Template:
id: CVE-2026-2614
info:
name: MLflow <= 3.9.0 - Arbitrary File Read
author: str4k3r
severity: high
description: |
mlflow mlflow <= 3.9.0 contains a path traversal caused by bypassing source path validation via the mlflow.prompt.is_prompt tag in CreateModelVersion request, letting unauthenticated remote attackers read arbitrary files.
impact: |
Unauthenticated attackers can read arbitrary files on the server, leading to complete confidentiality compromise.
remediation: |
Upgrade to version 3.10.0 or later.
reference:
- ht
https://github.com/mlflow/mlflow/commit/6e801f4259d96804c73107315b24cef0f6aa115ahttps://huntr.com/bounties/19380271-3fbf-4beb-987e-6fd7069c55e6https://access.redhat.com/errata/RHSA-2026:34456https://access.redhat.com/errata/RHSA-2026:37275https://access.redhat.com/errata/RHSA-2026:60520https://access.redhat.com/security/cve/CVE-2026-2614https://bugzilla.redhat.com/show_bug.cgi?id=2469309https://huntr.com/bounties/19380271-3fbf-4beb-987e-6fd7069c55e6https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2614.json
2026-05-11
Published
Exploited in the wild