20 August 2026
Reference: CVE-2026-64849
1. What is being reported?
The vulnerability involves a part of MLflow that handles webhooks, which are automated messages sent between systems. Before the fixed version 3.15.0, MLflow did not properly check where these webhook messages were sent, allowing attackers to redirect requests to internal or cloud services and see responses that should be private.
2. What this means in plain English
If your organisation uses MLflow, an attacker could exploit this flaw to access internal information or cloud service details that are not meant to be public. This could lead to data leaks or further attacks on your systems.
3. Could this affect a small business?
Small businesses or charities using MLflow, especially versions before 3.15.0, could be affected. If you do not use MLflow or similar AI engineering platforms, this vulnerability likely does not impact you.
4. What to do now
- Check if your organisation uses MLflow and identify the version installed.
- If using MLflow, update to version 3.15.0 or later as soon as possible.
- If an update is not immediately possible, consult your IT provider about applying any available mitigations or workarounds.
- Review your systems for unusual activity and ensure your cloud services are securely configured.
5. Ask your IT provider
Can you confirm if our MLflow installation is affected by CVE-2026-64849 and ensure it is updated to version 3.15.0 or later to protect against this vulnerability?
6. Bottom line
If you use MLflow, update it now to prevent attackers from exploiting this critical security flaw.
Information based on CISA KEV, NVD and reputable security reporting.