CVE Explorer
CVE-2026-2734
In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` GraphQL query lack proper per-model authorization checks when basic authentication is enabled. This allows any authenticated user to enumerate all model versions across all registered models, regardless of their permission level. The issue arises due to the absence of `SearchModelVersions` in the `BEFORE_REQUEST_VALIDATORS` and `AFTER_REQUEST_HANDLERS` for the REST API, and its
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"mlflow/mlflow","vendor":"mlflow","versions":[{"lessThan":"3.10.0","status":"affected","version":"unspecified","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:06ee30eb1d39f78c1f0a3313c534f9687bd06ba2275f6fb215427f84114f9a41 · sha256:c6e3c6e4a8a49b74… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.0"},"metric_type":"cvssV3_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:06ee30eb1d39f78c1f0a3313c534f9687bd06ba2275f6fb215427f84114f9a41 · sha256:c6e3c6e4a8a49b74… · /containers/cna/metrics/0/cvssV3_0
CWE assertions
1 source assertion{"cweId":"CWE-284","description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:06ee30eb1d39f78c1f0a3313c534f9687bd06ba2275f6fb215427f84114f9a41 · sha256:c6e3c6e4a8a49b74… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"url":"https://github.com/mlflow/mlflow/commit/6989066af33fdcb03588fd71a1a67f8fc5ef12c9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:06ee30eb1d39f78c1f0a3313c534f9687bd06ba2275f6fb215427f84114f9a41 · sha256:c6e3c6e4a8a49b74… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://huntr.com/bounties/d632f783-b2c7-4a3b-af5e-1d693e841c08"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:06ee30eb1d39f78c1f0a3313c534f9687bd06ba2275f6fb215427f84114f9a41 · sha256:c6e3c6e4a8a49b74… · /containers/adp/0/references/0
{"url":"https://huntr.com/bounties/d632f783-b2c7-4a3b-af5e-1d693e841c08"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:06ee30eb1d39f78c1f0a3313c534f9687bd06ba2275f6fb215427f84114f9a41 · sha256:c6e3c6e4a8a49b74… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.