A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schema CRUD API. Such manipulation leads to missing authorization. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. A reply to the GitHub issue explains, that "[t]he labeling schema PR has not been merged yet. The auth handlers will be added before the release."
Metrics
Affected Vendors & Products
References
History
Sun, 28 Jun 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schema CRUD API. Such manipulation leads to missing authorization. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. A reply to the GitHub issue explains, that "[t]he labeling schema PR has not been merged yet. The auth handlers will be added before the release." | |
| Title | MLflow Experiment-scoped Label Schema CRUD API authorization | |
| First Time appeared |
Mlflow
Mlflow mlflow |
|
| Weaknesses | CWE-862 CWE-863 |
|
| CPEs | cpe:2.3:a:mlflow:mlflow:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mlflow
Mlflow mlflow |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-28T08:30:09.086Z
Reserved: 2026-06-27T15:45:07.800Z
Link: CVE-2026-13484
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-28T10:30:05Z