PT-2026-45906 · Mlflow · Mlflow

Published

2026-06-03

·

Updated

2026-06-05

·

CVE-2026-4035

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions mlflow versions prior to 3.11.0
Description An issue allows for the resolution of environment variables in AI Gateway secrets, enabling the exfiltration of sensitive server-side environment credentials to an attacker-controlled endpoint. This occurs because the api key field in gateway secrets accepts $ENV VAR references, which the MLflow server resolves during runtime and sends in provider authentication headers to the configured upstream api base. The flaw can be exploited by unauthenticated users in default deployments or low-privileged authenticated users in basic-auth deployments. Potential impacts include the leakage of cloud artifact credentials such as AWS ACCESS KEY ID and AWS SECRET ACCESS KEY, which may lead to artifact poisoning and cross-boundary code execution in downstream environments.
Recommendations Update to version 3.11.0.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BIT-MLFLOW-2026-4035
CVE-2026-4035

Affected Products

Mlflow