2026-08-20HIGHexploitedCISA catalogued it as exploited on 19 August, and the default MLflow server needs no authentication to reach the webhook that does the fetching
MLflow, unauthenticated full-read SSRF in webhook delivery; the URL guard validates the resolved address but never pins it, and delivery follows redirects unvalidated. CISA KEV 2026-08-19; fixed in 3.15.0.
cve · CVE-2026-64849
Coverage
1
first 2026-08-20 → last 2026-08-20
Latest activity
2026-08-20
CISA catalogued it as exploited on 19 August, and the default MLflow server needs no authentication to reach…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, finance, energy
Sources cited
3
3 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-64849, newest first. Check the date before acting on an older one.
- Upgrade every MLflow tracking server to 3.15.0, which validates the peer address of the connected socket rather than the hostname at registration; where an upgrade has to wait, deny outbound traffic from the tracking-server host to link-local and RFC1918 destinations, because the reachable /test endpoint is what makes the server fetch on an attacker's behalf.2026-08-20CVE-2026-64849
- Where an MLflow tracking server has been reachable from an untrusted network on a build below 3.15.0, treat the credentials its instance role or attached service account can mint as exposed and rotate them, the read primitive returns the metadata response body directly to the caller, so exposure does not require any further foothold.2026-08-20CVE-2026-64849
Defender insights
What each entry about CVE-2026-64849 tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- Credential AccessUnsecured Credentials: Cloud Instance Metadata API
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-20/cve-2026-64849-mlflow-webhook-ssrf-redirect-bypass-kev · ATT&CK page ↗
Credential Access TA0006
T1552.005Unsecured Credentials: Cloud Instance Metadata API×1
Adversaries may attempt to access the Cloud Instance Metadata API to collect credentials and other sensitive data.
Evidence: 2026-08-20/cve-2026-64849-mlflow-webhook-ssrf-redirect-bypass-kev · ATT&CK page ↗
Entries about MLflow, unauthenticated full-read SSRF in webhook delivery; the URL guard validates the resolved address but never pins it, and delivery follows redirects unvalidated. CISA KEV 2026-08-19; fixed in 3.15.0. (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- MLflow×1
Where this entity is cited
Source distribution
- cisa.gov1 (33%)
- github.com1 (33%)
- osv.dev1 (33%)
External references
All cited sources (3)
- osv.devprimaryGitHub Security Advisory GHSA-7gwp-5pfp-969j (read via the OSV.dev mirror)https://osv.dev/vulnerability/GHSA-7gwp-5pfp-969j
- cisa.govCISA Known Exploited Vulnerabilities cataloghttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- github.comMLflow (fixing pull request)https://github.com/mlflow/mlflow/pull/24258