CVE-2025-11200: MLflow Weak Password Requirements Authentication Bypass Vulnerability
MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of passwords. The issue results from weak password requirements. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-26916.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11200?
CVE-2025-11200 has a critical severity level as it allows remote attackers to bypass authentication without needing credentials.
How do I fix CVE-2025-11200?
To fix CVE-2025-11200, update MLflow to a version that includes the patched authentication mechanism.
What versions of MLflow are affected by CVE-2025-11200?
CVE-2025-11200 affects all versions of MLflow prior to the release that addresses the vulnerability.
Can CVE-2025-11200 be exploited remotely?
Yes, CVE-2025-11200 can be exploited remotely as it does not require authentication or any user interaction.
What impact does CVE-2025-11200 have on security?
CVE-2025-11200 significantly increases the risk of unauthorized access and data breaches in MLflow installations.