Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 28 Jun 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schema CRUD API. Such manipulation leads to missing authorization. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. A reply to the GitHub issue explains, that "[t]he labeling schema PR has not been merged yet. The auth handlers will be added before the release." | |
| Title | MLflow Experiment-scoped Label Schema CRUD API authorization | |
| First Time appeared |
Mlflow
Mlflow mlflow |
|
| Weaknesses | CWE-862 CWE-863 |
|
| CPEs | cpe:2.3:a:mlflow:mlflow:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mlflow
Mlflow mlflow |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-28T08:30:09.086Z
Reserved: 2026-06-27T15:45:07.800Z
Link: CVE-2026-13484
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-28T10:30:05Z