THREAT OPS › Threat News › [NVD] CVE-2026-2614 (HIGH 7.5) — A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem. The issue arises when a `CreateModelVersion` request
[NVD] CVE-2026-2614 (HIGH 7.5) — A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem. The issue arises when a `CreateModelVersion` request
CVE-2026-2614 CVSS: 7.5 HIGH Published: 2026-05-11T20:25:41.423
A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem. The issue arises when a `CreateModelVersion` request includes the tag `mlflow.prompt.is_prompt`, which bypa
Indicators of compromise
- CVE-2026-2614cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-2614