• Sources: MLflow issue 24179, CISA Known Exploited Vulnerabilities catalog, a rolling feed, MLflow pull request 24258
  • Summary: CISA added CVE-2026-64849 on 2026-08-19 with a remediation date of 2026-09-02. The reported mechanism is a DNS rebinding bypass of MLflow webhook SSRF protection. Validation resolves the hostname and discards the resolved IP, then the request re-resolves independently, so an attacker-controlled DNS server can return a public IP for the check and 169.254.169.254 for the request. The issue states the webhook creation handler carries no permission decorator, so any authenticated user can reach cloud instance metadata and retrieve the IAM credentials of the MLflow server role. The same catalog took four further additions on 2026-08-18, each carrying a 2026-08-21 remediation date: CVE-2026-59310 in VMware vCenter, CVE-2026-55040 in SharePoint, CVE-2026-65400 in macOS, and CVE-2026-33824 in Windows IKE Service Extensions. Affected versions are not yet known here for any of the five: no MLflow version or version range was resolved for CVE-2026-64849, and the four catalog entries name the affected products without build numbers.
  • Why it matters: The catalog entry is the authoritative claim that the MLflow flaw is exploited rather than theoretical, and it reaches instance metadata credentials from an ordinary authenticated account.
  • Follow-up: Establish the affected MLflow version range, track whether pull request 24258 lands in a tagged MLflow release, and read the VMware, Microsoft, and Apple advisories behind the four 2026-08-18 additions for affected builds and for the mechanism of each. CISA describes them as a vCenter path traversal reaching arbitrary code execution, a SharePoint weak authentication flaw allowing a security feature bypass, a macOS improper authentication flaw allowing network authentication to Screen Sharing without credentials, and a Windows double free that could enable remote code execution. No vendor advisory was read this run.

send feedback on this story