CVE-2026-13484

LOW CVSS 4.0: 1.3 EPSS 0.31%
Updated Jul 01, 2026
Lfprojects
Parameter Value
CVSS 1.3 (LOW)
Affected Versions before 2026-05-26
Type CWE-862 (Missing Authorization), CWE-863 (Incorrect Authorization)
Vendor Lfprojects
Public PoC No

A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schema CRUD API. Such manipulation leads to missing authorization.

It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is regarded as difficult.

The exploit has been disclosed to the public and may be used. A reply to the GitHub issue explains, that "[t]he labeling schema PR has not been merged yet. The auth handlers will be added before the release."

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v4.0

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Lfprojects Mlflow
cpe:2.3:a:lfprojects:mlflow:*:*:*:*:*:*:*:*
<= 2026-05-26