CVE-2026-2652 is a high-severity authentication bypass vulnerability in MLflow affecting version 3.9.0 and earlier. The issue occurs when MLflow is started with authentication enabled using the basic-auth application mode and is served via uvicorn in ASGI mode. Under this deployment model, FastAPI route protection is inconsistently applied: the permission middleware only enforces authentication for paths under /gateway/, while other FastAPI endpoints are left accessible without credentials. The root cause is an architectural mismatch between Flask and FastAPI authentication handling. Specifically, the FastAPI validator selection logic fails to assign an authentication validator to non-gateway FastAPI routes, causing the middleware to treat those requests as unauthenticated-but-allowed. As a result, unauthenticated remote attackers can access sensitive FastAPI-backed functionality including job management and trace ingestion endpoints despite the server being explicitly configured to require authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
/gateway/ routes to include the affected FastAPI endpoints, including job-related APIs and trace ingestion, and adds tests to ensure unauthenticated requests are rejected with HTTP 401 responses. Any deployment running MLflow 3.9.0 or earlier in the affected configuration should be updated promptly.No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication bypass vulnerability affecting MLflow versions prior to 3.10.0, apparently related to FastAPI routing.
An authentication bypass vulnerability in MLflow's FastAPI middleware that allows unauthenticated access to protected job and trace endpoints on MLflow servers configured with authentication enabled and served via uvicorn.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.