CVE-2026-2611: CWE-346 Origin Validation Error in mlflow mlflow/mlflow
In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cross-origin requests from a malicious webpage to interact with the MLflow Assistant running on a victim's local machine. By bypassing the loopback-only restriction, the attacker can modify the Assistant's configuration to enable full access, which in turn allows the execution of arbitrary commands via the Claude Code sub-agent. This issue is resolved in version 3.10.0.
AI Analysis
Technical Summary
CVE-2026-2611 is a critical vulnerability (CVSS 9.6) in MLflow version 3.9.0 involving improper origin validation (CWE-346) in the MLflow Assistant's /ajax-api endpoints. This weakness allows remote attackers to bypass loopback-only restrictions by exploiting cross-origin requests from malicious web pages. Successful exploitation lets attackers alter the Assistant's configuration to enable full access, which leads to arbitrary command execution via the Claude Code sub-agent. The vulnerability affects versions >=3.9.0 and <3.10.0 and is fixed in version 3.10.0. No known exploits in the wild have been reported. The vendor advisory from Red Hat confirms the issue and its resolution.
Potential Impact
An attacker can remotely bypass origin restrictions to interact with the MLflow Assistant on a victim's local machine. This enables modification of the Assistant's configuration to gain full access, resulting in the ability to execute arbitrary commands. The impact includes complete confidentiality, integrity, and availability compromise of the affected system.
Mitigation Recommendations
Upgrade MLflow to version 3.10.0 or later, where this vulnerability is fixed. The vendor advisory confirms the fix is available in 3.10.0. No other mitigations are indicated by the vendor advisory.
CVE-2026-2611: CWE-346 Origin Validation Error in mlflow mlflow/mlflow
Description
In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cross-origin requests from a malicious webpage to interact with the MLflow Assistant running on a victim's local machine. By bypassing the loopback-only restriction, the attacker can modify the Assistant's configuration to enable full access, which in turn allows the execution of arbitrary commands via the Claude Code sub-agent. This issue is resolved in version 3.10.0.
CVSS v3.0
Score 9.6critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-2611 is a critical vulnerability (CVSS 9.6) in MLflow version 3.9.0 involving improper origin validation (CWE-346) in the MLflow Assistant's /ajax-api endpoints. This weakness allows remote attackers to bypass loopback-only restrictions by exploiting cross-origin requests from malicious web pages. Successful exploitation lets attackers alter the Assistant's configuration to enable full access, which leads to arbitrary command execution via the Claude Code sub-agent. The vulnerability affects versions >=3.9.0 and <3.10.0 and is fixed in version 3.10.0. No known exploits in the wild have been reported. The vendor advisory from Red Hat confirms the issue and its resolution.
Potential Impact
An attacker can remotely bypass origin restrictions to interact with the MLflow Assistant on a victim's local machine. This enables modification of the Assistant's configuration to gain full access, resulting in the ability to execute arbitrary commands. The impact includes complete confidentiality, integrity, and availability compromise of the affected system.
Mitigation Recommendations
Upgrade MLflow to version 3.10.0 or later, where this vulnerability is fixed. The vendor advisory confirms the fix is available in 3.10.0. No other mitigations are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- @huntr_ai
- Date Reserved
- 2026-02-17T02:36:47.412Z
- Cvss Version
- 3.0
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-2611","vendor":"Red Hat"}]
Threat ID: 6a0c3632ec166c07b08eb0ef
Added to database: 05/19/2026, 10:06:42 UTC
Last enriched: 07/15/2026, 08:10:40 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 158
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.