Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Attackers are exploiting a Server-Side Request Forgery (SSRF) vulnerability in MLflow to steal cloud credentials and secrets. The vulnerability, CVE-2026-64849, allows an attacker to reach cloud metadata services directly and exfiltrate sensitive data. Organizations runni…
Intelligence analysis by Llama

Attackers are exploiting a critical vulnerability in MLflow to steal cloud credentials and secrets. The vulnerability, CVE-2026-64849, allows an attacker to reach cloud metadata services directly and exfiltrate sensitive data. Organizations running MLflow are recommended to prioritize patching affected systems and review audit logs for signs of compromise.
Imagine you have a super powerful computer that can do lots of things, but it's also very vulnerable to attacks. That's what's happening with MLflow, a system that helps people use artificial intelligence. Attackers are finding ways to get into the system and steal important information. This is like a big security problem that needs to be fixed.
Analysis
MLflow Vulnerability Overview
The recent discovery of CVE-2026-64849, a Server-Side Request Forgery (SSRF) vulnerability in MLflow, has highlighted the potential for attackers to steal cloud credentials and secrets. This vulnerability allows an attacker to reach cloud metadata services directly and exfiltrate sensitive data.
Impact of the Vulnerability
The impact of this vulnerability is significant, as it allows attackers to gain unauthorized access to sensitive data. This can lead to a range of consequences, including data breaches, identity theft, and financial loss.
Exploitation of the Vulnerability
The exploitation of CVE-2026-64849 has been detected by watchTowr, a threat intelligence firm. According to their report, attackers are indiscriminately scanning for exposed MLflow instances online, with the goal of exploiting the vulnerability and stealing sensitive data.
Recommendations for Organizations
Organizations running MLflow are recommended to prioritize patching affected systems and review audit logs for signs of compromise. This will help to prevent the exploitation of CVE-2026-64849 and minimize the risk of data breaches and other security incidents.
Key points
- CVE-2026-64849 is a critical vulnerability in MLflow that allows attackers to steal cloud credentials and secrets.
- The vulnerability allows attackers to reach cloud metadata services directly and exfiltrate sensitive data.
- Organizations running MLflow are recommended to prioritize patching affected systems and review audit logs for signs of compromise.
- The exploitation of CVE-2026-64849 has been detected by watchTowr, a threat intelligence firm.
- Attackers are indiscriminately scanning for exposed MLflow instances online, with the goal of exploiting the vulnerability and stealing sensitive data.
If organizations prioritize patching affected systems and review audit logs for signs of compromise, they can minimize the risk of data breaches and other security incidents. This will help to prevent the exploitation of CVE-2026-64849 and ensure the security of sensitive data.
If organizations fail to prioritize patching affected systems and review audit logs for signs of compromise, they may be vulnerable to data breaches and other security incidents. This can lead to significant financial loss, identity theft, and reputational damage.



