VDB

CVE-2026-0545

CVE-2026-0545 PUBLISHED CVSS 9.100000381469727 CRITICAL

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled (`MLFLOW_SERVER_ENABLE_JOB_EXECUTION=true`) and any job function is allowlisted, any network client can submit, read, search, and cancel jobs without credentials, bypassing basic-auth entirely. This can lead to unauthenticated remote code execution if allowed jobs perform privileged actions such as shell execution or filesystem changes. Even if jobs are deemed safe, this still constitutes an authentication bypass, potentially resulting in job spam, denial of service (DoS), or data exposure in job results.

EPSS 10.82% · 93.5th percentile

Risk Scores

CVSS v3.0
9.100000381469727
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
10.82%
93.5th percentile

Affected Products

VendorProductVersions
mlflowmlflow/mlflowunspecified

Timeline

  • Apr 5, 2023 CrowdSec Sighting
  • Apr 3, 2026 CVE Published
  • Apr 3, 2026 PoC Published
  • Apr 4, 2026 Security Advisory
  • Apr 6, 2026 CVE Updated
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›