CVE-2026-2635 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installation…
Critical CVSS: 9.8

CVE-2026-2635

MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the basic_auth.ini file. The file contains hard-coded default credentials. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of the administrator. Was ZDI-CAN-28256.
Vendor
-
Product
-
CWE
CWE-1393
Yayın Tarihi
2026-02-20 23:16:05
Güncelleme
2026-02-23 18:13:53
Source Identifier
zdi-disclosures@trendmicro.com
KEV Date Added
-

Kategoriler

Referanslar