PT-2026-45906 · Mlflow · Mlflow
Published
2026-06-03
·
Updated
2026-06-05
·
CVE-2026-4035
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
mlflow versions prior to 3.11.0
Description
An issue allows for the resolution of environment variables in AI Gateway secrets, enabling the exfiltration of sensitive server-side environment credentials to an attacker-controlled endpoint. This occurs because the
api key field in gateway secrets accepts $ENV VAR references, which the MLflow server resolves during runtime and sends in provider authentication headers to the configured upstream api base. The flaw can be exploited by unauthenticated users in default deployments or low-privileged authenticated users in basic-auth deployments. Potential impacts include the leakage of cloud artifact credentials such as AWS ACCESS KEY ID and AWS SECRET ACCESS KEY, which may lead to artifact poisoning and cross-boundary code execution in downstream environments.Recommendations
Update to version 3.11.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mlflow