CVE-2026-13484

A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schema CRUD API. Such manipulation leads to missing authorization. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. A reply to the GitHub issue explains, that "[t]he labeling schema PR has not been merged yet. The auth handlers will be added before the release."
References
Link Resource
https://github.com/mlflow/mlflow/ Product
https://github.com/mlflow/mlflow/issues/23608 Issue Tracking Third Party Advisory Exploit
https://github.com/mlflow/mlflow/issues/23608#issuecomment-4560963877 Third Party Advisory VDB Entry Exploit Issue Tracking
https://vuldb.com/cve/CVE-2026-13484 Third Party Advisory VDB Entry
https://vuldb.com/submit/837658 Third Party Advisory VDB Entry
https://vuldb.com/vuln/374481 Third Party Advisory VDB Entry
https://vuldb.com/vuln/374481/cti Permissions Required VDB Entry
https://github.com/mlflow/mlflow/issues/23608#issuecomment-4560963877 Third Party Advisory VDB Entry Exploit Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*

History

01 Jul 2026, 14:03

Type Values Removed Values Added
First Time Lfprojects mlflow
Lfprojects
CPE cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*
References () https://github.com/mlflow/mlflow/ - () https://github.com/mlflow/mlflow/ - Product
References () https://github.com/mlflow/mlflow/issues/23608 - () https://github.com/mlflow/mlflow/issues/23608 - Issue Tracking, Third Party Advisory, Exploit
References () https://github.com/mlflow/mlflow/issues/23608#issuecomment-4560963877 - () https://github.com/mlflow/mlflow/issues/23608#issuecomment-4560963877 - Third Party Advisory, VDB Entry, Exploit, Issue Tracking
References () https://vuldb.com/cve/CVE-2026-13484 - () https://vuldb.com/cve/CVE-2026-13484 - Third Party Advisory, VDB Entry
References () https://vuldb.com/submit/837658 - () https://vuldb.com/submit/837658 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/374481 - () https://vuldb.com/vuln/374481 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/374481/cti - () https://vuldb.com/vuln/374481/cti - Permissions Required, VDB Entry

30 Jun 2026, 19:16

Type Values Removed Values Added
References () https://github.com/mlflow/mlflow/issues/23608#issuecomment-4560963877 - () https://github.com/mlflow/mlflow/issues/23608#issuecomment-4560963877 -

28 Jun 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-28 09:16

Updated : 2026-07-01 14:03


NVD link : CVE-2026-13484

Mitre link : CVE-2026-13484

CVE.ORG link : CVE-2026-13484


JSON object : View

Products Affected

lfprojects

  • mlflow
CWE
CWE-862

Missing Authorization

CWE-863

Incorrect Authorization