
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33866 is an authorization bypass vulnerability in MLflow affecting the AJAX endpoint used to download saved model artifacts (GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files). Due to missing access-control validation, an authenticated user with low privileges can directly query this endpoint and retrieve model artifacts from experiments they are not authorized to access. All MLflow versions through 3.10.1 are affected; the fix was introduced in version 3.11.0rc0. It carries a CVSS v3.1 base score of 4.3 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (GitHub Advisory, Feedly).
The root cause is CWE-862 (Missing Authorization): the AJAX artifact download endpoint GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files is a plain Flask route rather than a gRPC service endpoint, so it was not included in the auto-generated LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS dictionary built from get_endpoints(). As a result, no validate_can_read_logged_model check was applied before serving artifact data. An attacker only needs a valid low-privilege account on the MLflow server; no special configuration or user interaction is required. A related endpoint, GET /api/2.0/mlflow/logged-models/<model_id>/artifacts/directories (ListLoggedModelArtifacts), was also found to lack authorization enforcement, allowing enumeration of artifact file names, paths, and sizes — a prerequisite for targeted artifact download (GitHub PR #21708, GitHub Advisory).
Successful exploitation allows any authenticated low-privilege user to exfiltrate model artifacts — including trained ML model weights, serialized pipelines, and associated files — from experiments they have no authorized access to. This represents a confidentiality breach that could expose proprietary intellectual property, sensitive training data embedded in model artifacts, or model architectures. There is no integrity or availability impact, and lateral movement beyond the MLflow artifact store is not directly enabled by this vulnerability alone (GitHub Advisory, Feedly).
A proof-of-concept exploit with detailed reproduction steps is publicly available, including a Python script that uploads a malicious artifact to a real MLflow tracking server and instructions for triggering the vulnerability (afine.com blog). The EPSS score is approximately 0.009% (1st percentile), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog. The vulnerability is detectable by Qualys (detection ID 5010628) (Feedly, GitHub Advisory).
GET /api/2.0/mlflow/logged-models/search) or the unprotected ListLoggedModelArtifacts endpoint (GET /api/2.0/mlflow/logged-models/<model_id>/artifacts/directories) to enumerate model IDs and artifact paths from experiments the attacker does not own.GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files?path=<artifact_path> using the attacker's session credentials./ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files from users or IP addresses not associated with the owning experiment; repeated requests to /api/2.0/mlflow/logged-models/<model_id>/artifacts/directories from low-privilege accounts.Upgrade MLflow to version 3.11.0rc0 or later, which adds validate_can_read_logged_model to LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS for the affected AJAX endpoint and also enforces authorization on ListLoggedModelArtifacts (GitHub PR #21708, GitHub Advisory). As a short-term workaround for deployments that cannot immediately upgrade, implement network segmentation to restrict access to the MLflow server to only authorized users and services, and review access logs for unauthorized artifact access attempts. Organizations should also audit experiment-level permissions and ensure the principle of least privilege is applied to all MLflow user accounts.
CERT-PL (the Polish national CERT) published a post covering related MLflow vulnerabilities discovered in the same research batch, referenced in the GitHub advisory (CERT-PL). Security firm Afine published a detailed technical blog post with PoC steps titled "Attacking MLflow: How ML Artifacts Become Attack Vectors," which was cited in the official GitHub advisory (afine.com blog). The vulnerability was also tracked by ENISA under EUVD-2026-19609 and flagged by Red Hat's security advisory system, indicating broad awareness across the European security community (Feedly).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."