CVE-2026-4035 Details
Description
A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because the `api_key` field in gateway secrets can accept `$ENV_VAR` references, which are resolved against the MLflow server's environment during runtime. The resolved secrets are then sent in provider authentication headers to the configured upstream `api_base`. This vulnerability can be exploited by low-privileged authenticated users in basic-auth deployments or by unauthenticated users in default deployments without `basic-auth`. The impact includes potential leakage of sensitive credentials such as cloud artifact credentials (`AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`), which could lead to artifact poisoning and cross-boundary code execution in downstream environments. The issue is fixed in version 3.11.0.
A vulnerability exists in MLflow versions prior to 3.11.0, where AI Gateway secrets can resolve environment variable references. This flaw allows low-privileged authenticated users in basic-auth deployments, or unauthenticated users in default deployments without basic-auth, to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. The issue stems from the 'api_key' field in gateway secrets accepting '$ENV_VAR' references, which are resolved at runtime and sent in authentication headers to the specified 'api_base'. Exploitation could lead to the leakage of critical credentials, such as cloud artifact credentials, potentially causing artifact poisoning and cross-boundary code execution in downstream environments.
Users can update to MLflow version 3.11.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-4035 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2484318 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4035.json | redhat-SADP | |
| https://huntr.com/bounties/f8e591a0-0f19-4910-b82e-16c9956f2233 | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/mlflow/mlflow/commit/4a3f2f720cb4f058c9e0c5b883e0acc9ab64a7f3 | [email protected] | Patch |
| https://huntr.com/bounties/f8e591a0-0f19-4910-b82e-16c9956f2233 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-201 | Insertion of Sensitive Information Into Sent Data | redhat-SADP |
| CWE-201 | Insertion of Sensitive Information Into Sent Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lfprojects mlflow | < 3.11.0 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 14, 2026 | CVE Modified | redhat-SADP |
| Jul 21, 2026 | CVE Translated | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 4, 2026 | Initial Analysis | [email protected] |
| Jun 3, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | New CVE Received | [email protected] |