CVE-2026-79721
Deferred Deferred - Pending Action

Code Execution in MLflow Platform via Malicious Model Artifacts

Vulnerability report for CVE-2026-79721, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: HiddenLayer

Description

Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-30
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mlflow mlflow From 0.0.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-829 The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows arbitrary code execution in MLflow versions 0.0.1 or newer. A malicious model artifact can execute code on a user's system when loaded by the project. The issue occurs because MLflow's model loading function reads configuration settings without proper validation, enabling attackers to manipulate these settings to run arbitrary Python code with the privileges of the loading process.

Detection Guidance

To detect this vulnerability, inspect MLflow model artifacts for suspicious MLmodel configuration files. Check for unexpected python_function.loader_module or code settings in the model's configuration. Review sys.path modifications during model loading for unauthorized directory additions.

Impact Analysis

If you load a malicious MLflow model artifact, an attacker could execute arbitrary code on your system. This could lead to data theft, system compromise, or further network infiltration. The attack can occur with locally stored or remotely hosted models, such as those accessed via URIs like runs:/ or models:/.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations using MLflow may face compliance breaches if attackers exploit this flaw to access sensitive data.

Mitigation Strategies

Immediately update MLflow to the latest patched version. Avoid loading untrusted model artifacts. Implement strict validation of MLmodel configuration files before loading. Restrict model artifact sources to trusted repositories only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79721. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart