PyPI: mlflow
CVE-2026-2651
Safety vulnerability ID: SFTY-20260526-04465
A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce resource-level permission checks for `/mlflow-artifacts/mpu/*` endpoints, enabling attackers to overwrite artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue is resolved in version 3.10.0.
Overview
MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
Advisory
MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20260526-04465/CVE-2026-2651
- https://nvd.nist.gov/vuln/detail/CVE-2026-2651
- https://github.com/mlflow/mlflow/commit/d7290811d8f3c95366d80109424edc1fb1ad966f
- https://huntr.com/bounties/65beb119-d3e0-4e03-af2f-fa98f78f83dc
- https://access.redhat.com/security/cve/CVE-2026-2651
- https://bugzilla.redhat.com/show_bug.cgi?id=2481117
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2651.json
- https://github.com/advisories/GHSA-8c7q-86fq-vvmh
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
