PyPI: mlflow
CVE-2026-2734
Safety vulnerability ID: SFTY-20260521-23243
Affected versions of the MLflow package are vulnerable to Information Disclosure due to lack of per-model permissions checks. The `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query fail to implement proper per-model authorization checks when basic authentication is enabled. An attacker with authenticated access can exploit this vulnerability to enumerate all model versions across registered models, exposing sensitive information such as model names, version descriptions, source URIs, tags, and other metadata.
Overview
MLflow authenticated users can enumerate any registered model versions due to lack of per-model permissions checks
Advisory
mlflow – Improper Access Control
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20260521-23243/CVE-2026-2734
- https://nvd.nist.gov/vuln/detail/CVE-2026-2734
- https://github.com/mlflow/mlflow/commit/6989066af33fdcb03588fd71a1a67f8fc5ef12c9
- https://huntr.com/bounties/d632f783-b2c7-4a3b-af5e-1d693e841c08
- https://github.com/advisories/GHSA-w5xq-c4pf-ghq7
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
