CVE-2026-69148: MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_sou...
Added to the CISA Known Exploited Vulnerabilities catalog on 17 Aug 2026. Vendor: AI/ML. Product: machine learning. CVSS score: 7.1.
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in mlflow/server/handlers.py verifies only path containment, a...
Required action: Review and patch if applicable to your AI infrastructure.