CVE-2026-13484
Gravedad CVSS v4.0:
BAJA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
28/06/2026
Última modificación:
01/07/2026
Descripción
*** Pendiente de traducción *** A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schema CRUD API. Such manipulation leads to missing authorization. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. A reply to the GitHub issue explains, that "[t]he labeling schema PR has not been merged yet. The auth handlers will be added before the release."
Impacto
Puntuación base 4.0
1.30
Gravedad 4.0
BAJA
Puntuación base 3.x
5.00
Gravedad 3.x
MEDIA
Puntuación base 2.0
4.60
Gravedad 2.0
MEDIA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:* | 2026-05-26 (incluyendo) |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://github.com/mlflow/mlflow/
- https://github.com/mlflow/mlflow/issues/23608
- https://github.com/mlflow/mlflow/issues/23608#issuecomment-4560963877
- https://vuldb.com/cve/CVE-2026-13484
- https://vuldb.com/submit/837658
- https://vuldb.com/vuln/374481
- https://vuldb.com/vuln/374481/cti
- https://github.com/mlflow/mlflow/issues/23608#issuecomment-4560963877



