CVE-2026-64849 is a critical unauthenticated Server-Side Request Forgery (SSRF) vulnerability in MLflow, an open-source AI platform. With a CVSS score of 9.3, it allows attackers to reach the MLflow Tracking Server and issue HTTP requests to arbitrary internal cloud metadata endpoints, potentially stealing cloud credentials and secrets. Affects versions prior to 3.15.0.