cbcvebase.
CVE-2026-2652
published 2026-05-15

CVE-2026-2652: A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with…

PriorityP185high8.6CVSS 3.0
AVNACLPRNUINSUCLIHAL
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
1.41%
71.7th percentile
A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) and served via uvicorn (ASGI). The FastAPI permission middleware only enforces authentication on `/gateway/` routes, leaving other routes such as the Job API (`/ajax-api/3.0/jobs/*`) and the OpenTelemetry trace ingestion API (`/v1/traces`) unprotected. This allows unauthenticated remote attackers to submit jobs, read job results, cancel running jobs, and inject arbitrary trace data into experiments. The issue arises from an architectural mismatch between Flask and FastAPI authentication mechanisms, where the `_find_fastapi_validator()` function fails to handle non-`/gateway/` paths, resulting in a complete authentication bypass. This vulnerability is fixed in version 3.10.0.

Affected

3 ranges
VendorProductVersion rangeFixed in
lfprojectsmlflow< 3.10.03.10.0
lfprojectsmlflow>= 0 < 3.11.03.11.0
mlflowmlflow_mlflow>= unspecified < 3.10.03.10.0

Detection & IOCsextracted from sources · hover to see the quote

path/ajax-api/3.0/jobs/*↗
path/v1/traces↗
path/ajax-api/3.0/jobs/search
path/api/2.0/mlflow/experiments/list
sigma
HTTP POST to /ajax-api/3.0/jobs/search returning 200 with body containing '"jobs":' without Authorization header
  • →The vulnerability is only present when MLflow is started with `--app-name basic-auth` and served via uvicorn (ASGI); Flask-based deployments are not affected by this specific bypass. ↗
  • →Use Shodan query `http.title:"mlflow"` or FOFA query `app="mlflow"` to identify exposed MLflow instances for targeted scanning.
  • ·The authentication bypass only affects MLflow deployments running with both `--app-name basic-auth` AND uvicorn (ASGI); standard Flask/WSGI deployments use a different auth mechanism and are not vulnerable to this specific bypass. ↗
  • ·Red Hat OpenShift AI (RHOAI) packages are confirmed not affected as the vulnerable code is not present in their builds. ↗

CVSS provenance

nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
vulncheck8.6HIGH
vendor_redhat8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.