CVE-2026-33866
EUVD-2026-1960907.04.2026, 13:16
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access‑control validation, a user without permissions to a given experiment can directly query this endpoint and retrieve model artifacts they are not authorized to access. This issue affects MLflow version through 3.10.1Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lfprojects | mlflow | 𝑥 ≤ 3.10.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration