CVE-2026-2635: 
MLflow vulnerability analysis and mitigation

Overview

CVE-2026-2635 is an authentication bypass vulnerability in MLflow caused by hard-coded default credentials in the basic_auth.ini configuration file. It was reported to the vendor on October 14, 2025, and publicly disclosed on February 19, 2026, via a coordinated release by the Zero Day Initiative (ZDI-26-111). The vulnerability affects MLflow installations (vendor: lfprojects/mlflow) and requires no authentication or user interaction to exploit. It carries a CVSS v3.0 base score of 9.8 (Critical) (ZDI Advisory, Feedly).

Technical details

The root cause is the use of hard-coded credentials (CWE-798) embedded in MLflow's basic_auth.ini file, which is used for authentication configuration. An unauthenticated remote attacker can supply these known default credentials over the network to bypass authentication entirely, gaining administrator-level access. Once authenticated as an administrator, the attacker can execute arbitrary code in the context of the administrator account. The fix, implemented in MLflow pull request #19260, also addressed a related artifact path traversal vector (ZDI-CAN-26649) by validating run directory structure in mlflow/store/tracking/file_store.py to prevent directory traversal via malicious meta.yaml files (ZDI Advisory, MLflow PR #19260).

Impact

Successful exploitation allows a remote, unauthenticated attacker to gain full administrator access to an MLflow installation, enabling arbitrary code execution in the administrator context. This results in high confidentiality, integrity, and availability impact — an attacker could exfiltrate sensitive ML model data, training datasets, and experiment metadata; tamper with models or pipelines; or disrupt MLflow services entirely. Given MLflow's role in ML infrastructure, compromise could facilitate lateral movement into connected data stores, model registries, or cloud environments (ZDI Advisory, Feedly).

Exploitability

A proof-of-concept exploit reference is available via the Zero Day Initiative advisory (ZDI-26-111), published February 19, 2026. As of the time of reporting, there is no confirmed evidence of active in-the-wild exploitation. The vulnerability is detected by Nessus (plugin 299880) and Qualys (QID 5009285). The EPSS score is approximately 0.0139 (1.39%), indicating a relatively low but non-negligible probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE (ZDI Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible MLflow instances using tools like Shodan, Censys, or internal network scanning. Look for the MLflow web UI (default port 5000) with basic authentication enabled.
  2. Identify default credentials: Locate or infer the hard-coded default credentials from the basic_auth.ini file, which are publicly known following the ZDI disclosure.
  3. Authenticate as administrator: Submit an HTTP request to the MLflow server using the hard-coded default credentials (e.g., via curl or a browser), bypassing the authentication mechanism and gaining administrator-level access.
  4. Execute arbitrary code: Leverage administrator privileges within MLflow to perform actions such as registering malicious model artifacts, exploiting the related path traversal vector via crafted meta.yaml files, or abusing MLflow's model serving and project execution features to achieve remote code execution on the underlying server.
  5. Establish persistence or pivot: Use the compromised MLflow instance to access connected data stores, cloud storage backends, or model registries, or deploy backdoored models for persistent access (ZDI Advisory, MLflow PR #19260).

Indicators of compromise

  • Network: Unexpected successful HTTP authentication attempts to the MLflow server from external or unusual IP addresses; repeated login attempts using default credentials followed by successful access.
  • Logs: MLflow access logs showing administrator-level API calls (e.g., model registration, artifact uploads, run creation) from previously unseen source IPs; authentication events using the default username from basic_auth.ini.
  • File System: Presence of unexpected or malicious meta.yaml files in artifact directories; new or modified files in MLflow artifact storage paths outside expected run directories; unexpected subdirectories (e.g., metrics/, params/, artifacts/) created in non-run locations.
  • Process: Unusual child processes spawned by the MLflow server process (e.g., shell commands, curl, wget, python scripts not initiated by legitimate users); unexpected outbound network connections from the MLflow host (ZDI Advisory, MLflow PR #19260).

Mitigation and workarounds

MLflow has issued a patch addressing this vulnerability, merged into the master branch on December 10, 2025, and tagged for inclusion in release v3.7.1 (MLflow PR #19260). Users should upgrade to MLflow v3.7.1 or later immediately. As a temporary workaround prior to patching, restrict network access to MLflow services using firewall rules or network-level access controls to limit exposure to trusted hosts only. Additionally, change any default credentials in basic_auth.ini to strong, unique values and audit all MLflow installations for signs of unauthorized access (ZDI Advisory, MLflow PR #19260).

Community reactions

The vulnerability was credited to Peter Girnus (@gothburz) of Trend Zero Day Initiative and received coverage from The Hacker Wire, which published an article titled "MLflow Default Password Auth Bypass Leads to RCE" (The Hacker Wire). Social media discussion appeared on Mastodon and Bluesky, with community members highlighting the severity of hard-coded credentials in ML infrastructure tooling. A Reddit thread on r/netsec discussed this CVE alongside 21 other AI/ML security advisories, reflecting broader community concern about security in ML platforms (Reddit).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related MLflow vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64849CRITICAL9.3
  • NixOS logoNixOS
  • mlflow
YesYesAug 17, 2026
GHSA-gqvg-gmmx-x4hmHIGH8.8
  • MLflow logoMLflow
  • mlflow
NoYesSep 01, 2026
CVE-2026-8147HIGH8.1
  • NixOS logoNixOS
  • mlflow
NoYesJul 02, 2026
CVE-2026-71211HIGH7.1
  • Wolfi logoWolfi
  • mlflow
NoYesAug 05, 2026
CVE-2026-10803LOW1.1
  • NixOS logoNixOS
  • mlflow
NoYesJun 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management