CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-64849: Critical SSRF in MLflow

August 18, 2026

CVE-2026-64849 is a critical unauthenticated Server-Side Request Forgery (SSRF) vulnerability in MLflow, an open-source AI platform. With a CVSS score of 9.3, it allows attackers to reach the MLflow Tracking Server and issue HTTP requests to arbitrary internal cloud metadata endpoints, potentially stealing cloud credentials and secrets. Affects versions prior to 3.15.0.