Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-64849 |
| Alert Source | CISA KEV - Active Exploitation |
| CVE Publication Year | 2026 |
| Date Published | 2026-08-19 |
| Vendor | MLflow |
| Product | MLflow |
| CVSS Score | 9.3 (critical) |
| EPSS Score | 1.1% (percentile: 63%) |
| CISA KEV | Yes - confirmed active exploitation |
| Ransomware | Not confirmed |
| Remediation Deadline | 2026-09-02 |
Vulnerability Description
MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.
Required Actions
This vulnerability is listed in CISA KEV — exploitation is confirmed, not hypothetical.
- Update MLflow to 3.15.0 or later. That is the only complete fix.
- Until you can update, cut off network access to the MLflow server from outside trusted segments. The endpoint is unauthenticated, so any exposure is an open door.
- Understand why SSRF matters here: MLflow servers usually sit on the same network as training data, artifact stores and cloud credentials. A request issued “from the inside” reaches what an external attacker cannot — including cloud instance metadata services.
- Run a compromise assessment, not just an update. A KEV listing means someone is already exploiting this. Check webhook endpoint access logs and unusual outbound requests from the MLflow host.
- Inventory your MLflow instances — they are often spun up by data science teams outside standard IT process and may not appear in the systems register.
Who Is Affected?
Organizations using MLflow for machine learning lifecycle management. Instances are often spun up by analytics teams outside standard IT process — the most common reason such a vulnerability goes unnoticed despite a CISA KEV listing.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
