CVE-2026-13484: Missing Authorization in MLflow
A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schema CRUD API. Such manipulation leads to missing authorization. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. A reply to the GitHub issue explains, that "[t]he labeling schema PR has not been merged yet. The auth handlers will be added before the release."
AI Analysis
Technical Summary
This vulnerability in MLflow up to commit 4666cffc7912ea606d592fc38d6a75e2935f65e7 allows remote attackers to perform unauthorized actions on the Experiment-scoped Label Schema CRUD API due to missing authorization checks. The attack complexity is high, and no privileges or user interaction are required. The labeling schema feature is still under development, and authorization controls are expected to be implemented before its official release. No known exploits are currently in the wild.
Potential Impact
The vulnerability could allow unauthorized remote manipulation of the Experiment-scoped Label Schema API in MLflow, potentially leading to unauthorized changes in labeling schema data. However, the attack complexity is high, and the feature is not yet released, limiting immediate impact. The CVSS score of 2.3 reflects a low severity with limited exploitability and impact.
Mitigation Recommendations
No official patch or fix is currently available. The vendor has indicated that authorization handlers will be added before the labeling schema feature is released. Users should monitor official MLflow releases and apply updates once the fix is published. Until then, caution is advised when using pre-release or development versions containing the labeling schema feature.
CVE-2026-13484: Missing Authorization in MLflow
Description
A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schema CRUD API. Such manipulation leads to missing authorization. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. A reply to the GitHub issue explains, that "[t]he labeling schema PR has not been merged yet. The auth handlers will be added before the release."
CVSS v4.0
Score 2.3low
Affected software
cpe:2.3:a:mlflow:mlflow:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in MLflow up to commit 4666cffc7912ea606d592fc38d6a75e2935f65e7 allows remote attackers to perform unauthorized actions on the Experiment-scoped Label Schema CRUD API due to missing authorization checks. The attack complexity is high, and no privileges or user interaction are required. The labeling schema feature is still under development, and authorization controls are expected to be implemented before its official release. No known exploits are currently in the wild.
Potential Impact
The vulnerability could allow unauthorized remote manipulation of the Experiment-scoped Label Schema API in MLflow, potentially leading to unauthorized changes in labeling schema data. However, the attack complexity is high, and the feature is not yet released, limiting immediate impact. The CVSS score of 2.3 reflects a low severity with limited exploitability and impact.
Mitigation Recommendations
No official patch or fix is currently available. The vendor has indicated that authorization handlers will be added before the labeling schema feature is released. Users should monitor official MLflow releases and apply updates once the fix is published. Until then, caution is advised when using pre-release or development versions containing the labeling schema feature.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-06-27T15:45:07.800Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a40e43027e9c79719a9e947
Added to database: 06/28/2026, 09:06:56 UTC
Last enriched: 07/05/2026, 22:53:46 UTC
Last updated: 08/11/2026, 02:26:54 UTC
Views: 124
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.