THREATOPS
THREAT OPSThreat News › MLflow Bug Actively Exploited to Steal Credentials

MLflow Bug Actively Exploited to Steal Credentials

medduo_decipherPublished 2026-08-18

<p class="wp-block-paragraph">Security researchers have identified a critical vulnerability in MLflow that exposes default tracking server installations to unauthenticated Server-Side Request Forgery (SSRF) and attackers are already exploiting it.</p>

<p class="wp-block-paragraph">This flaw allows remote, unauthenticated attackers to read sensitive data from internal network services or cloud m

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://decipher.sc/2026/08/18/mlflow-bug-actively-exploited-to-steal-credentials/