Get real-time updates on Telegram
P4Verified
MLflow Server-Side Request Forgery Vulnerability
CVE-2026-64849. CVSS base score 9.3 (CRITICAL, Vendor/CNA). EPSS 0.09839 (percentile 0.95427), scored 2026-10-04.
- CVE
- CVE-2026-64849
- CWE
- CWE-918
- CCR priority
- 39.7 /100 (P4)
- CVSS
- 9.3 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N · Vendor/CNA
- EPSS
- 0.09839 · percentile 0.95427 · 2026-10-04
- KEV
- no
Affected products
- cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-05 23:09:08.830529+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-64849.html