CVE-2026-92568: MLRun through 1.11.0 Server-Side Request Forgery via Webhook

Published Sep 16, 2026
·
Updated

MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to internal addresses. Attackers can update a run with a malicious webhook notification that executes when the run reaches a terminal state, enabling requests to internal services, Kubernetes APIs, or cloud metadata endpoints from within the cluster.

Affected Software

1 affected component
MLRun MLRun<1.11.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MLRun to a version that resolves this vulnerability.

    Fixed in 1.11.0
  2. Compensating control

    Restrict network egress from the MLRun component handling WebhookNotification so the Kubernetes API server cannot reach internal addresses, Kubernetes APIs, or cloud metadata endpoints from within the cluster.

Event History

Sep 16, 2026
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated MLRun user who can update a run and configure its webhook notification can exploit it. The malicious request is sent only when the affected run reaches a terminal state.

2

What systems could be reached through the vulnerable server?

The MLRun API server can be induced to make arbitrary HTTP requests to internal addresses. The advisory specifically identifies internal services, Kubernetes APIs, and cloud metadata endpoints reachable from within the cluster.

3

Are deployments affected by default?

The available information does not establish whether webhook notifications are enabled or usable by default. Exposure depends on whether authenticated users can update runs with webhook notifications and whether the API server can reach sensitive internal endpoints.

4

What can be done before an update is available?

Restrict which authenticated users can update runs or configure webhook notifications. Limit network access from the MLRun API server to internal services, Kubernetes APIs, and cloud metadata endpoints where feasible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203