THREAT OPS › Threat News › [NVD] CVE-2026-0545 (CRITICAL 9.8) — In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled (`MLFLOW_SERVER_ENABLE_
[NVD] CVE-2026-0545 (CRITICAL 9.8) — In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled (`MLFLOW_SERVER_ENABLE_
CVE-2026-0545 CVSS: 9.8 CRITICAL Published: 2026-04-03T18:16:21.540
In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled (`MLFLOW_SERVER_ENABLE_JOB_EXECUTION=true`) and any job function is allowl
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-0545cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-0545