Skip to content
MLflowGHSA-gq3w-7jj3-x7gr

MLflow Use of Default Password Authentication Bypass Vulnerability

Critical9.8CVE-2026-2635 · Published Feb 21, 2026 · updated Sep 10, 2026

This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the basic_auth.ini file. The file contains hard-coded default credentials. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of the administrator.

GitHub advisory

Affected versions

PackageAffectedFixed in
mlflow
PyPI
< 3.8.0rc03.8.0rc0
Details and references

More MLflow advisories

All MLflow
Advisory
MLFlow path traversal vulnerability
Critical9.6Mar 30
MLFlow allows Tracing + Assessments Access
High8.1Mar 27
Arbitrary file write via tar traversal in mlflow
High8.1Mar 19
MLflow has a command injection in mlflow/sagemaker/__init__.py
High7.5Mar 16
MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
High8.1Feb 21
mlflow Creates of Temporary File in Directory with Insecure Permissions
High7.0Feb 2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.