CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-2651: mlflow < 3.10.0

CVE-2026-2651 affects mlflow. CVSS 3.0 base score 9.0 (GitHub Advisory Database). EPSS 0.00536 (percentile 0.43244), scored 2026-10-05. Affected range: < 3.10.0. Fixed version: 3.10.0.

Affected technology

mlflow · < 3.10.0
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (GitHub Advisory Database, CVSS 3.0): Network (remote) · Low privileges required · User interaction required

What an attacker can do

The source reports that an attacker could run attacker-chosen code under the conditions described by the source. GitHub Advisory Database’s CVSS 3.0 assessment rates confidentiality, integrity and availability impact as high.

Published

Product
mlflow
CCR priority
36.1 /100 (P4)
CVSS 3.0
9.0 /10 · CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H · GitHub Advisory Database
EPSS
0.00536 · percentile 0.43244 · 2026-10-05
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-2651.html