CVE-2026-79721: MLflow MLflow platform vulnerability
Published Sep 8, 2026
·Updated
Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.
Affected Software
1 affected component
MLflow MLflow platform>=undefined
Event History
Sep 8, 2026
CVE Published
via MITRE·06:10 PM
Data Sourced
via MITRE·06:10 PM
DescriptionWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
End users who load maliciously crafted model artifacts with affected MLflow platform versions are exposed, because loading the artifact can execute arbitrary code on their system.
2
What must an attacker provide to trigger exploitation?
An attacker needs to supply a maliciously crafted model artifact that is then loaded by the project.
3
Are default installations affected?
The available information identifies MLflow platform version 0.0.1 or newer as affected, but it does not state whether exploitation requires any non-default configuration.