In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the late…
Critical CVSS 9.8
Summary
In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled (`MLFLOW_SERVER_ENABLE_JOB_EXECUTION=true`) and any job function is allowlisted, any network client can submit, read, search, and cancel jobs without credentials, bypassing basic-auth entirely. This can lead to unauthenticated remote code exe…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://huntr.com/bounties/b2e5b028-9541-4d29-8703-a76f1a3734d8 Exploit
- https://access.redhat.com/security/cve/CVE-2026-0545
- https://bugzilla.redhat.com/show_bug.cgi?id=2454889
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0545.json
Timeline
- nvd_ingest NVD