MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
High8.1CVE-2026-2033 · Published Feb 21, 2026 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mlflow PyPI | < 3.8.0rc0 | 3.8.0rc0 |
Details and references
MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MLflow Tracking Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of artifact file paths. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the service account.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2026-2033, PYSEC-2026-2658
More MLflow advisories
All MLflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 21 | MLflow Use of Default Password Authentication Bypass Vulnerability CVE-2026-2635Critical9.8fixed in 3.8.0rc0 | Critical9.8 | 3.8.0rc0 |
| Feb 2 | mlflow Creates of Temporary File in Directory with Insecure Permissions CVE-2025-10279High7.0fixed in 3.4.0rc0 | High7.0 | 3.4.0rc0 |
| Mar 16 | MLflow has a command injection in mlflow/sagemaker/__init__.py CVE-2025-14287High7.5fixed in 3.8.0rc0 | High7.5 | 3.8.0rc0 |
| Mar 19 | Arbitrary file write via tar traversal in mlflow CVE-2025-15031High8.1fixed in 3.9.0rc0 | High8.1 | 3.9.0rc0 |
| Mar 27 | MLFlow allows Tracing + Assessments Access CVE-2025-15381High8.1no fix yet | High8.1 | No fix yet |
| Mar 30 | MLFlow path traversal vulnerability CVE-2025-15036Critical9.6fixed in 3.9.0rc0 | Critical9.6 | 3.9.0rc0 |