THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-68772 (HIGH 8.0) — ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can replace a stored artifact.pkl file

[NVD] CVE-2026-68772 (HIGH 8.0) — ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can replace a stored artifact.pkl file

mednvdPublished 2026-08-07

CVE-2026-68772 CVSS: 8.0 HIGH Published: 2026-08-07T17:17:07.573

ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can replace a stored artifact.pkl file with a crafted cloudpickle payload containing a malici

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-68772