CVE-2026-2614 carries a CVSS 3.1 base score of 7.5 against MLflow, an open-source machine-learning lifecycle platform. NVD classifies it under both instances of CWE-22 (Path Traversal) and states the flaw is fixed in version 3.10.0, affecting version 3.9.0 and earlier. VulnCheck’s KEV feed reports the CVE as exploited, dated August 29, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-2614 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description locates the flaw in the _create_model_version() handler of MLflow’s server code. NVD states a CreateModelVersion API request carrying a specific tag associated with marking a model version as a “prompt” (a distinct MLflow object type) causes the handler to skip its normal source-path validation, allowing an attacker to register an arbitrary local filesystem path as that model version’s source. NVD states a separate handler, get_model_version_artifact_handler(), later serves files from that stored source path without re-checking whether the model version is actually a prompt, resulting in unauthenticated arbitrary file read.
We are deliberately not reproducing the specific tag value NVD’s description identifies as triggering the validation bypass, since doing so would function as a directly usable exploitation instruction rather than vulnerability reporting; readers needing that detail for authorized testing or patch verification should consult the linked vendor fix commit.
Evidence and confidence
- Medium confidence — the CVSS 7.5 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), the CWE-22 classification, the fixed version (3.10.0), and the described mechanism all trace to NVD alone in our current ingestion, corroborated by the project’s own fix commit and a huntr.com bug-bounty record. The exploitation report traces to VulnCheck KEV alone. - High exploitation probability — FIRST’s EPSS model scores this CVE at 0.03608, an 88.9th percentile score as of our ingestion — notably high for a VulnCheck-only listing.
No field is in conflict between our two sources.
Why this matters
MLflow’s model registry is designed to be a centralized, often internally shared component of an organization’s machine-learning pipeline, and NVD describes the resulting impact as “complete confidentiality compromise” — meaning any file readable by the MLflow server process, not just model artifacts, is potentially exposed. Organizations running MLflow model registries that are reachable by untrusted users, even internal ones without legitimate registry access, should treat this as a high-priority patch given the unauthenticated nature of the bypass and the high EPSS percentile.
Frequently Asked Questions
What is CVE-2026-2614? A CVSS 7.5 path traversal vulnerability (CWE-22) in MLflow’s model registry, versions 3.9.0 and earlier, allowing unauthenticated attackers to read arbitrary files from the server’s filesystem by bypassing source-path validation on a model version registration request.
Is CVE-2026-2614 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 29, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Do I need an account to exploit this? No. NVD’s description confirms this is exploitable by an unauthenticated remote attacker.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which version fixes this? Version 3.10.0, per NVD and the project’s own fix commit.
Severity, vector, weakness classification, and mechanism sourced from the National Vulnerability Database record for CVE-2026-2614, corroborated by MLflow’s own fix commit and its huntr.com bug-bounty record. Exploitation status and the August 29, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.