Hackers Are Exploiting an MLflow Bug to Steal Cloud Credentials Within Hours of Disclosure

Started by VoidKnight, Yesterday at 08:31 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Hackers Are Exploiting an MLflow Bug to Steal Cloud Credentials Within Hours of Disclosure   Views(Read 40 times)
Active members in this topic:
VoidKnight(1) Ronaldo(1)

VoidKnight

CISA has added a critical MLflow vulnerability to its Known Exploited Vulnerabilities catalog and given federal agencies until September 2 to patch it, after security firm watchTowr detected active exploitation attempts hitting its honeypot network within hours of the flaw even being assigned a CVE number. MLflow is a widely used open source platform, backed by the Linux Foundation, for managing machine learning models, and it reportedly gets more than 60 million monthly downloads.

The vulnerability itself, tracked as CVE-2026-64849 with a CVSS score of 9.3, is a server side request forgery issue in MLflow's webhook testing feature. On a default MLflow Tracking Server, anyone who can reach the service can create a webhook and trigger a test without ever logging in, and that test can be abused to make the server issue HTTP requests to internal only systems it would never normally be allowed to reach on the attacker's behalf, including cloud metadata endpoints that hold temporary but genuinely powerful identity credentials.

What makes this particularly dangerous is exactly the kind of access those metadata endpoints can leak. Successful exploitation can hand an attacker AWS Identity and Access Management credentials, service account tokens, environment variables, and other secrets sitting on whatever internal cloud infrastructure the exposed MLflow server happens to be running inside of, essentially turning a machine learning experiment tracking tool into a launchpad for a much broader cloud account compromise.

The flaw affects every MLflow version before 3.15.0, and while MLflow did add some outbound destination validation back in version 3.10.0 specifically to stop webhooks from reaching private or reserved IP addresses, that protection apparently only applied to the initial hostname a request was aimed at, leaving a gap attackers could still route around. watchTowr's honeypot data shows attackers indiscriminately scanning for exposed MLflow deployments almost immediately after the CVE was publicly assigned, rather than carefully targeting specific known organizations.

Because MLflow is so often treated as just a convenient local tool for experimenting with AI models rather than genuine production infrastructure, plenty of teams likely have an exposed instance running somewhere they have never actually thought to secure

Ronaldo

MLflow being treated as just a local experimentation tool by so many teams rather than genuine production infrastructure is exactly the mismatch that keeps producing these exact kinds of severe vulnerabilities across the AI tooling ecosystem lately. Nobody applies the same security rigor to something they think of as a developer's personal sandbox.

Save money on everyday spending Free cashback on thousands of retailers
View offer