PyPI: mlflow

CVE-2026-2734

Safety vulnerability ID: SFTY-20260521-23243

Affected versions of the MLflow package are vulnerable to Information Disclosure due to lack of per-model permissions checks. The `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query fail to implement proper per-model authorization checks when basic authentication is enabled. An attacker with authenticated access can exploit this vulnerability to enumerate all model versions across registered models, exposing sensitive information such as model names, version descriptions, source URIs, tags, and other metadata.

Created at: Jul 23, 2026Updated at: Jul 23, 2026

Overview

MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks

Advisory

mlflow – Improper Access Control

Affected Package

Affecting mlflow package, versions
< 3.10.0

Also affects

---

How to Fix

Upgrade
mlflow
to
3.10.0
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more