CVE intelligence
CVE-2026-64849
MLflow Server-Side Request Forgery Vulnerability
Lfprojects · Published 2026-08-17 · CVSS CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Changed
CConfidentiality- High
IIntegrity- Low
AAvailability- None
critical · KEV listed 2026-08-19 · Action due 2026-09-02
NIST record