CVE-2026-0545
mlflow mlflow/mlflow, Red Hat OpenShift AI (RHOAI), mlflow
In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled (`MLFLOW_SERVER_ENABLE_JOB_EXECUTION=true`) and any job function is allowlisted, any network client can submit, read, search, and cancel jobs without credentials, bypassing basic-auth entirely. This can lead to unauthenticated remote code execution if allowed jobs perform privileged actions such as shell execution or filesystem changes. E...
- CVSS
- 9.8
- EPSS
- 4.39% 90.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.04