
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2635 is an authentication bypass vulnerability in MLflow caused by hard-coded default credentials in the basic_auth.ini configuration file. It was reported to the vendor on October 14, 2025, and publicly disclosed on February 19, 2026, via a coordinated release by the Zero Day Initiative (ZDI-26-111). The vulnerability affects MLflow installations (vendor: lfprojects/mlflow) and requires no authentication or user interaction to exploit. It carries a CVSS v3.0 base score of 9.8 (Critical) (ZDI Advisory, Feedly).
The root cause is the use of hard-coded credentials (CWE-798) embedded in MLflow's basic_auth.ini file, which is used for authentication configuration. An unauthenticated remote attacker can supply these known default credentials over the network to bypass authentication entirely, gaining administrator-level access. Once authenticated as an administrator, the attacker can execute arbitrary code in the context of the administrator account. The fix, implemented in MLflow pull request #19260, also addressed a related artifact path traversal vector (ZDI-CAN-26649) by validating run directory structure in mlflow/store/tracking/file_store.py to prevent directory traversal via malicious meta.yaml files (ZDI Advisory, MLflow PR #19260).
Successful exploitation allows a remote, unauthenticated attacker to gain full administrator access to an MLflow installation, enabling arbitrary code execution in the administrator context. This results in high confidentiality, integrity, and availability impact — an attacker could exfiltrate sensitive ML model data, training datasets, and experiment metadata; tamper with models or pipelines; or disrupt MLflow services entirely. Given MLflow's role in ML infrastructure, compromise could facilitate lateral movement into connected data stores, model registries, or cloud environments (ZDI Advisory, Feedly).
A proof-of-concept exploit reference is available via the Zero Day Initiative advisory (ZDI-26-111), published February 19, 2026. As of the time of reporting, there is no confirmed evidence of active in-the-wild exploitation. The vulnerability is detected by Nessus (plugin 299880) and Qualys (QID 5009285). The EPSS score is approximately 0.0139 (1.39%), indicating a relatively low but non-negligible probability of exploitation in the near term. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE (ZDI Advisory, Feedly).
basic_auth.ini file, which are publicly known following the ZDI disclosure.curl or a browser), bypassing the authentication mechanism and gaining administrator-level access.meta.yaml files, or abusing MLflow's model serving and project execution features to achieve remote code execution on the underlying server.basic_auth.ini.meta.yaml files in artifact directories; new or modified files in MLflow artifact storage paths outside expected run directories; unexpected subdirectories (e.g., metrics/, params/, artifacts/) created in non-run locations.curl, wget, python scripts not initiated by legitimate users); unexpected outbound network connections from the MLflow host (ZDI Advisory, MLflow PR #19260).MLflow has issued a patch addressing this vulnerability, merged into the master branch on December 10, 2025, and tagged for inclusion in release v3.7.1 (MLflow PR #19260). Users should upgrade to MLflow v3.7.1 or later immediately. As a temporary workaround prior to patching, restrict network access to MLflow services using firewall rules or network-level access controls to limit exposure to trusted hosts only. Additionally, change any default credentials in basic_auth.ini to strong, unique values and audit all MLflow installations for signs of unauthorized access (ZDI Advisory, MLflow PR #19260).
The vulnerability was credited to Peter Girnus (@gothburz) of Trend Zero Day Initiative and received coverage from The Hacker Wire, which published an article titled "MLflow Default Password Auth Bypass Leads to RCE" (The Hacker Wire). Social media discussion appeared on Mastodon and Bluesky, with community members highlighting the severity of hard-coded credentials in ML infrastructure tooling. A Reddit thread on r/netsec discussed this CVE alongside 21 other AI/ML security advisories, reflecting broader community concern about security in ML platforms (Reddit).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."