CRITICAL 9.8 PyPI
MLflow Use of Default Password Authentication Bypass Vulnerability
GHSA-gq3w-7jj3-x7gr · CVE-2026-2635
Published · Modified
Description
This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the basic_auth.ini file. The file contains hard-coded default credentials. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of the administrator.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-2635
- WEB https://github.com/mlflow/mlflow/pull/19260
- WEB https://github.com/mlflow/mlflow/commit/5bf2ec2bd4222a18d78631183ac7f6b752afe8a4
- PACKAGE https://github.com/mlflow/mlflow
- WEB https://github.com/mlflow/mlflow/releases/tag/v3.8.0rc0
- WEB https://www.zerodayinitiative.com/advisories/ZDI-26-111
Ready to move
Start Securing
Free, no credit card | First findings in minutes