MLflowGHSA-gq3w-7jj3-x7gr
MLflow Use of Default Password Authentication Bypass Vulnerability
Critical9.8CVE-2026-2635 · Published Feb 21, 2026 · updated Sep 10, 2026
This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the basic_auth.ini file. The file contains hard-coded default credentials. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of the administrator.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mlflow PyPI | < 3.8.0rc0 | 3.8.0rc0 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-1393
- Also known as
- CVE-2026-2635, PYSEC-2026-421
More MLflow advisories
All MLflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 30 | MLFlow path traversal vulnerability | Critical9.6 | 3.9.0rc0 |
| Mar 27 | MLFlow allows Tracing + Assessments Access | High8.1 | No fix yet |
| Mar 19 | Arbitrary file write via tar traversal in mlflow | High8.1 | 3.9.0rc0 |
| Mar 16 | MLflow has a command injection in mlflow/sagemaker/__init__.py | High7.5 | 3.8.0rc0 |
| Feb 21 | MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability | High8.1 | 3.8.0rc0 |
| Feb 2 | mlflow Creates of Temporary File in Directory with Insecure Permissions | High7.0 | 3.4.0rc0 |