PT-2025-40607 · Databricks · Mlflow

Published

2025-10-03

·

Updated

2025-11-06

·

CVE-2025-11200

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MLflow (affected versions not specified)
Description This issue allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this flaw, which stems from weak password requirements. An attacker can leverage this to bypass authentication on the system. Approximately 5,400 instances are potentially exposed. The vulnerability exists within the handling of passwords.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MLFLOW-2025-11200
CVE-2025-11200
GHSA-6XJ8-RRQX-R4CV
ZDI-25-932

Affected Products

Mlflow