A security flaw has been identified in MLflow, a tool used to manage machine learning workflows that some users run on their hosting accounts. This is a server-side request forgery (SSRF) vulnerability, a type of weakness that lets attackers trick the MLflow service into sending requests to systems that are meant to be private and inaccessible from the public internet. If exploited, this flaw could allow bad actors to access internal network services or cloud metadata tools, and retrieve the data these systems send back in response. This may expose sensitive information about your hosting environment, including configuration details, cloud account credentials, or other private data that should never be publicly accessible.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-64849