THREAT OPS › Threat News › [NVD] CVE-2026-68772 (HIGH 8.0) — ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can replace a stored artifact.pkl file
[NVD] CVE-2026-68772 (HIGH 8.0) — ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can replace a stored artifact.pkl file
CVE-2026-68772 CVSS: 8.0 HIGH Published: 2026-08-07T17:17:07.573
ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can replace a stored artifact.pkl file with a crafted cloudpickle payload containing a malici
Indicators of compromise
- CVE-2026-68772cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-68772