ZDI-CAN-26916: ZDI-25-932: MLflow Weak Password Requirements Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of passwords. The issue results from weak password requirements. An attacker can leverage this vulnerability to bypass authentication on the system.
Other sources
This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2025-11200.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-26916?
The severity of ZDI-CAN-26916 is rated 8.1 on the CVSS scale.
How does ZDI-CAN-26916 affect MLflow installations?
ZDI-CAN-26916 allows remote attackers to bypass authentication on affected MLflow installations.
Is authentication required to exploit ZDI-CAN-26916?
No, authentication is not required to exploit the ZDI-CAN-26916 vulnerability.
What versions of MLflow are affected by ZDI-CAN-26916?
All versions of MLflow are affected by ZDI-CAN-26916.
What is the associated CVE for ZDI-CAN-26916?
The associated CVE for ZDI-CAN-26916 is CVE-2025-11200.