CVE-2026-0545 describes a critical authentication bypass vulnerability in MLflow, where FastAPI job endpoints are not protected by basic authentication. This allows unauthenticated network clients to submit, read, search, and cancel jobs, potentially leading to unauthenticated remote code execution if job execution is enabled and allowlisted jobs perform privileged actions. Rated 9.1 Critical (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N), it has a low attack complexity and requires no user interaction or privileges. Although no public exploit code or active exploitation is confirmed, it is on the "Hot List" and has received community attention due to its severe impact potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:lfprojects:mlflow:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.