CVE-2026-33866: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-33866 is an authorization bypass vulnerability in MLflow affecting the AJAX endpoint used to download saved model artifacts (GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files). Due to missing access-control validation, an authenticated user with low privileges can directly query this endpoint and retrieve model artifacts from experiments they are not authorized to access. All MLflow versions through 3.10.1 are affected; the fix was introduced in version 3.11.0rc0. It carries a CVSS v3.1 base score of 4.3 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (GitHub Advisory, Feedly).

Technical details

The root cause is CWE-862 (Missing Authorization): the AJAX artifact download endpoint GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files is a plain Flask route rather than a gRPC service endpoint, so it was not included in the auto-generated LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS dictionary built from get_endpoints(). As a result, no validate_can_read_logged_model check was applied before serving artifact data. An attacker only needs a valid low-privilege account on the MLflow server; no special configuration or user interaction is required. A related endpoint, GET /api/2.0/mlflow/logged-models/<model_id>/artifacts/directories (ListLoggedModelArtifacts), was also found to lack authorization enforcement, allowing enumeration of artifact file names, paths, and sizes — a prerequisite for targeted artifact download (GitHub PR #21708, GitHub Advisory).

Impact

Successful exploitation allows any authenticated low-privilege user to exfiltrate model artifacts — including trained ML model weights, serialized pipelines, and associated files — from experiments they have no authorized access to. This represents a confidentiality breach that could expose proprietary intellectual property, sensitive training data embedded in model artifacts, or model architectures. There is no integrity or availability impact, and lateral movement beyond the MLflow artifact store is not directly enabled by this vulnerability alone (GitHub Advisory, Feedly).

Exploitability

A proof-of-concept exploit with detailed reproduction steps is publicly available, including a Python script that uploads a malicious artifact to a real MLflow tracking server and instructions for triggering the vulnerability (afine.com blog). The EPSS score is approximately 0.009% (1st percentile), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog. The vulnerability is detectable by Qualys (detection ID 5010628) (Feedly, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify an accessible MLflow server (version ≤ 3.10.1) using MLflow Authentication. Obtain a low-privilege account (e.g., a free trial or shared workspace account) that has no READ permission on the target experiment.
  2. Enumerate model IDs: Use the authenticated session to query the MLflow API (e.g., GET /api/2.0/mlflow/logged-models/search) or the unprotected ListLoggedModelArtifacts endpoint (GET /api/2.0/mlflow/logged-models/<model_id>/artifacts/directories) to enumerate model IDs and artifact paths from experiments the attacker does not own.
  3. Craft the bypass request: Directly issue an HTTP GET request to the unprotected AJAX endpoint: GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files?path=<artifact_path> using the attacker's session credentials.
  4. Retrieve unauthorized artifacts: Because no authorization validator is applied to this endpoint, the server returns the requested artifact file (e.g., model weights, serialized objects) without checking experiment-level READ permissions.
  5. Exfiltrate data: Download and analyze the retrieved model artifacts for proprietary model architectures, embedded training data, or other sensitive information (GitHub PR #21708, afine.com blog).

Indicators of compromise

  • Network: Unexpected HTTP GET requests to /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files from users or IP addresses not associated with the owning experiment; repeated requests to /api/2.0/mlflow/logged-models/<model_id>/artifacts/directories from low-privilege accounts.
  • Logs: MLflow access logs showing successful (HTTP 200) responses to artifact download endpoints for users who do not have READ permission on the parent experiment; cross-referencing user identity in access logs against experiment ACLs will reveal mismatches.
  • Behavioral: A single low-privilege user account querying artifact endpoints across multiple experiment model IDs in rapid succession, particularly for experiments they did not create or are not members of.

Mitigation and workarounds

Upgrade MLflow to version 3.11.0rc0 or later, which adds validate_can_read_logged_model to LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS for the affected AJAX endpoint and also enforces authorization on ListLoggedModelArtifacts (GitHub PR #21708, GitHub Advisory). As a short-term workaround for deployments that cannot immediately upgrade, implement network segmentation to restrict access to the MLflow server to only authorized users and services, and review access logs for unauthorized artifact access attempts. Organizations should also audit experiment-level permissions and ensure the principle of least privilege is applied to all MLflow user accounts.

Community reactions

CERT-PL (the Polish national CERT) published a post covering related MLflow vulnerabilities discovered in the same research batch, referenced in the GitHub advisory (CERT-PL). Security firm Afine published a detailed technical blog post with PoC steps titled "Attacking MLflow: How ML Artifacts Become Attack Vectors," which was cited in the official GitHub advisory (afine.com blog). The vulnerability was also tracked by ENISA under EUVD-2026-19609 and flagged by Red Hat's security advisory system, indicating broad awareness across the European security community (Feedly).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management