← Vulnerability feed

Vulnerability record · CVE-2026-64849 · published 17 August 2026

CVE-2026-64849: MLflow unauthenticated webhook test endpoint SSRF via redirect

Lfprojects · Mlflow

MLflow before 3.15.0 validates the webhook URL only on the original request, while the delivery code follows redirects and re-resolves the hostname without pinning the validated address. An unauthenticated attacker can therefore make the server fetch internal or cloud metadata endpoints and read back response_status and response_body. It matters because it exposes internal services and cloud credentials to anyone who can reach the API.

9.3 CVSS 3.1 Critical CISA KEV since 19 Aug 2026 EPSS 9.8% · top 4.6% CWE-918 · Server-side request forgery (SSRF)
9.3CVSS 3.1 base score
9.8%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
6References, 2 tagged exploit
20 Aug 2026Last modified by NVD

Description

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable SSRF with CVSS 9.3, KEV listing and exploit-tagged references, exposing internal services and cloud metadata.

What it is

MLflow before 3.15.0 validates the webhook URL only on the original request, while the delivery code follows redirects and re-resolves the hostname without pinning the validated address. An unauthenticated attacker can therefore make the server fetch internal or cloud metadata endpoints and read back response_status and response_body. It matters because it exposes internal services and cloud credentials to anyone who can reach the API.

Impact

An attacker gains server-side requests to internal networks and cloud metadata services, with response status and body returned to the caller. That can disclose credentials, tokens and internal service data, and the CVSS scope change reflects impact beyond the MLflow component.

Attack surface

Reached over the network through the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint; no authentication or user interaction is required per the vector AV:N/AC:L/PR:N/UI:N. The attacker only needs network access to the MLflow API.

Exploitation

CISA added it to KEV on 2026-08-19 with a 2026-09-02 due date, and references carry Exploit tags, indicating known exploitation. EPSS 30-day probability is 0.1641 (96.8th percentile), so exploitation is plausible at scale.

What to do

  • Upgrade MLflow to 3.15.0 or later, which contains the fix.
  • If immediate upgrade is not possible, restrict network access to the MLflow API and block outbound traffic from MLflow hosts to internal ranges and cloud metadata addresses (for example 169.254.169.254).
  • Require authentication and authorization on the webhook test endpoint and any other unauthenticated administrative API paths.
  • Apply CISA BOD 26-04 guidance, including evaluating internet exposure of MLflow instances and discontinuing use where mitigations are unavailable.
  • Review webhook configurations and remove or disable unused webhook endpoints.

Detection

  • Monitor MLflow logs and outbound network flows for requests from MLflow hosts to internal RFC1918 addresses, loopback, or cloud metadata endpoints.
  • Alert on POST requests to /api/2.0/mlflow/webhooks/*/test, especially from unauthenticated or unexpected sources.
  • Inspect webhook URLs and redirect chains for hostnames that resolve to internal or metadata IPs, and flag responses returning response_body content from such targets.
  • Hunt for cloud metadata credential access patterns (for example requests to 169.254.169.254) originating from MLflow server processes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-64849 to the Known Exploited Vulnerabilities catalog on 19 August 2026 as "MLflow Server-Side Request Forgery Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 2 September 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-64849 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-15379Lfprojects mlflow command injection vulnerabilityA command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to…EPSS 2.4%10.0CVE-2025-15036Lfprojects mlflow path traversal vulnerabilityA path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlf…EPSS 0.58%10.0CVE-2023-3765MLflow absolute path traversal before 2.5.0MLflow versions prior to 2.5.0 contain an absolute path traversal flaw (CWE-36) in the GitHub repository mlflow/mlflow. The vulnerability allows an u…EPSS 68%analysed9.8CVE-2026-0545Lfprojects mlflow missing authentication for critical function vulnerabilityIn mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` a…EPSS 4.4%9.8CVE-2025-11200Lfprojects mlflow weak password requirements vulnerabilityMLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affecte…EPSS 1.5%9.8CVE-2025-11201Lfprojects mlflow path traversal vulnerabilityMLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute …EPSS 27%9.8CVE-2023-6974Lfprojects mlflow server-side request forgery (ssrf) vulnerabilityA malicious user could use this issue to access internal HTTP(s) servers and in the worst case (ie: aws instance) it could be abuse to get a remote c…EPSS 1.5%9.8CVE-2023-6975Lfprojects mlflow vulnerabilityA malicious user could use this issue to get command execution on the vulnerable machine and get access to data & models information.EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2026-64849), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.