A high-severity security issue has been identified in MLflow. Designated as CVE-2026-64849, this vulnerability involves server-side request forgery (SSRF) and requires prompt attention from organizations using the software in their environments.

Security teams and system administrators need clear, actionable details to understand the risk and secure their infrastructure properly without relying on speculation.

What Happened

  • Vulnerability Type: Server-Side Request Forgery (SSRF)
  • Affected Product: MLflow
  • Impact: Attackers can potentially reach internal or cloud metadata services and receive both response status and response body data.
  • CISA Status: This issue is officially tracked on CISA's Known Exploited Vulnerabilities (KEV) list, indicating that active exploitation has been observed in the wild.

You can review the specific details directly on the Korisec CVE-2026-64849 tracker page.

Who Should Care

Organizations and small businesses running MLflow instances exposed to networks should treat this advisory with urgency. Because this flaw is actively tracked on the KEV list, the risk of external targeting is elevated. If your infrastructure hosts internal endpoints or cloud metadata services accessible from your MLflow deployment, unauthorized parties could interact with those sensitive resources.

What to Do Now

Securing your environment against server-side request forgery requires systematic verification:

  1. Inventory Deployments: Identify every instance of MLflow running across your internal networks, staging environments, and production systems.
  2. Review Access Controls: Ensure that network segmentation restricts your MLflow servers from reaching sensitive internal resources, local loopback interfaces, and cloud metadata endpoints.
  3. Apply Updates: Check with the vendor for the latest security advisories and apply available patches promptly.

Proactive vulnerability management is essential for maintaining a strong security posture. To check your external-facing systems for known issues, you can run a free security check at Korisec.