CVE-2026-13484 Details
Description
A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schema CRUD API. Such manipulation leads to missing authorization. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. A reply to the GitHub issue explains, that "[t]he labeling schema PR has not been merged yet. The auth handlers will be added before the release."
A vulnerability exists in MLflow versions prior to the latest commit on June 26, 2026, within the Experiment-Scoped Label Schema CRUD API. This vulnerability allows authenticated users to bypass authorization checks, enabling unauthorized access to create, read, update, and delete label schemas. The issue arises because the new label schema API routes do not have the necessary authorization validators registered, leading to a failure in enforcing the required permission checks. The vulnerability can be exploited remotely and is associated with a high level of complexity.
The vulnerability has been addressed in the MLflow repository. Users should update to the latest version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/mlflow/mlflow/issues/23608#issuecomment-4560963877 | CISA-ADP | Third Party AdvisoryVDB EntryExploitIssue Tracking |
| https://github.com/mlflow/mlflow/ | [email protected] | Product |
| https://github.com/mlflow/mlflow/issues/23608 | [email protected] | Issue TrackingThird Party AdvisoryExploit |
| https://github.com/mlflow/mlflow/issues/23608#issuecomment-4560963877 | [email protected] | Third Party AdvisoryVDB EntryExploitIssue Tracking |
| https://vuldb.com/cve/CVE-2026-13484 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/submit/837658 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/vuln/374481 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/vuln/374481/cti | [email protected] | Permissions RequiredVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lfprojects mlflow | <= 2026-05-26 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | Initial Analysis | [email protected] |
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 28, 2026 | New CVE Received | [email protected] |