Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw Found in Popular AI Platform MLflow

A serious security weakness has been found in MLflow, an open-source platform used for managing AI and machine learning models. This flaw allows attackers to trick the system into accessing internal services, potentially exposing sensitive information. The issue is actively being exploited, making it important for organisations using MLflow to act quickly.

20 August 2026

Reference: CVE-2026-64849

1. What is being reported?

The vulnerability involves a part of MLflow that handles webhooks, which are automated messages sent between systems. Before the fixed version 3.15.0, MLflow did not properly check where these webhook messages were sent, allowing attackers to redirect requests to internal or cloud services and see responses that should be private.

2. What this means in plain English

If your organisation uses MLflow, an attacker could exploit this flaw to access internal information or cloud service details that are not meant to be public. This could lead to data leaks or further attacks on your systems.

3. Could this affect a small business?

Small businesses or charities using MLflow, especially versions before 3.15.0, could be affected. If you do not use MLflow or similar AI engineering platforms, this vulnerability likely does not impact you.

4. What to do now

  • Check if your organisation uses MLflow and identify the version installed.
  • If using MLflow, update to version 3.15.0 or later as soon as possible.
  • If an update is not immediately possible, consult your IT provider about applying any available mitigations or workarounds.
  • Review your systems for unusual activity and ensure your cloud services are securely configured.

5. Ask your IT provider

Can you confirm if our MLflow installation is affected by CVE-2026-64849 and ensure it is updated to version 3.15.0 or later to protect against this vulnerability?

6. Bottom line

If you use MLflow, update it now to prevent attackers from exploiting this critical security flaw.

Information based on CISA KEV, NVD and reputable security reporting.

Back to Vulnerability Briefs