Skip to content
Threat Feed
high advisory

Multiple Vulnerabilities in MLflow Enabling Arbitrary Code Execution

Multiple vulnerabilities in MLflow, identified as CVE-2023-6976, CVE-2023-6977, and CVE-2023-6978, allow remote attackers to execute arbitrary code due to improper input validation and insecure deserialization.

CVE search metadata

CVE search record: CVE-2023-6976. Severity: high. CVSS: 8.8. EPSS: 1.02%. KEV: no. Product: MLflow. Brief: Multiple Vulnerabilities in MLflow Enabling Arbitrary Code Execution. Brief link: https://feed.craftedsignal.io/briefs/2026-09-mlflow-code-execution/

CVE search record: CVE-2023-6977. Severity: high. CVSS: 7.5. EPSS: 3.92%. KEV: no. Product: MLflow. Brief: Multiple Vulnerabilities in MLflow Enabling Arbitrary Code Execution. Brief link: https://feed.craftedsignal.io/briefs/2026-09-mlflow-code-execution/

The MLflow platform, managed by the LF AI & Data Foundation, is susceptible to multiple vulnerabilities that allow for remote code execution (RCE). These vulnerabilities, tracked under CVE-2023-6976, CVE-2023-6977, and CVE-2023-6978, arise from weaknesses in input validation and insecure deserialization processes within the software. These flaws enable an unauthenticated or low-privileged attacker to inject malicious payloads into the MLflow environment, leading to full system compromise. Given MLflow's common role in machine learning pipelines, a successful exploit could grant an attacker access to sensitive model data, training parameters, and the underlying infrastructure running the MLflow server or tracking components. Defenders should prioritize patching and assess exposure of MLflow instances to untrusted networks.

Impact

Successful exploitation of these vulnerabilities allows an attacker to achieve arbitrary code execution on the server hosting MLflow. This level of access facilitates full environment compromise, potentially resulting in data exfiltration, tampering with machine learning model artifacts, and lateral movement within the network. These vulnerabilities represent a high risk for organizations leveraging MLflow for MLOps, particularly in cloud-native or research environments where the platform may be exposed to broader network segments.

Recommendation

Prioritize patching all MLflow installations to the latest version where these CVEs are addressed. As immediate mitigation, ensure that MLflow tracking servers are restricted to trusted internal networks and utilize robust authentication mechanisms. Review server logs for suspicious API requests or unexpected process execution patterns originating from the MLflow service account.


Immediate actions

Patch MLflow instances to the vendor-recommended version remediating CVE-2023-6976, CVE-2023-6977, and CVE-2023-6978

IT Operations 48h

Mitigations

Restrict network access to MLflow instances to authorized internal segments

immediate Network Security

CVE-2023-6976, CVE-2023-6977, CVE-2023-6978