Vulnerability record · CVE-2024-25723 · published 27 February 2024
CVE-2024-25723: ZenML Server activate endpoint allows remote privilege escalation
Zenml · Zenml
ZenML Server before 0.46.7 exposes the /api/v1/users/{user_name_or_id}/activate REST endpoint, which grants access based on a valid username plus a new password supplied in the request body. This improper access control lets an attacker take over accounts, including privileged ones, on affected ZenML deployments.
Description
ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on the basis of a valid username along with a new password in the request body. These are also patched versions: 0.44.4, 0.43.1, and 0.42.2.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and high EPSS, but no confirmed in-the-wild exploitation or KEV listing.
What it is
ZenML Server before 0.46.7 exposes the /api/v1/users/{user_name_or_id}/activate REST endpoint, which grants access based on a valid username plus a new password supplied in the request body. This improper access control lets an attacker take over accounts, including privileged ones, on affected ZenML deployments.
Impact
An attacker who knows or guesses a valid username can set a new password and activate that account, escalating privileges and gaining full control of the ZenML server and its data.
Attack surface
Reachable over the network via the REST API endpoint /api/v1/users/{user_name_or_id}/activate; the CVSS vector indicates low privileges are required and no user interaction, though the description suggests a valid username and new password in the body are sufficient.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged, but EPSS is very high (0.70785, 99.4th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade ZenML to 0.46.7 or later; if that is not possible, apply the patched versions 0.44.4, 0.43.1, or 0.42.2.
- Restrict network access to the ZenML Server API so only trusted clients can reach it.
- Audit and rotate credentials for all ZenML user accounts, especially administrative ones.
- Monitor the /api/v1/users/{user_name_or_id}/activate endpoint for unexpected or unauthorized activation requests.
Detection
- Review ZenML server logs for calls to /api/v1/users/*/activate, particularly from unusual source IPs or for privileged accounts.
- Alert on password changes or account activations that occur outside normal administrative workflows.
- Correlate authentication events with subsequent privileged API actions to spot account takeover attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-25723 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-25723), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.