SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84452

HIGH · CVSS 8.6 EPSS 0.95% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Windows ML CLI tool prior to version 0.4.0 is vulnerable due to an unauthenticated localhost HTTP API that allows cross-origin requests, enabling attackers to execute arbitrary code on the server. This high-severity flaw can be exploited by malicious websites to manipulate the command-line flags, leading to potential system compromise. Organizations using affected versions should prioritize upgrading to version 0.4.0 to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84452
Severity
HIGH
CVSS
8.6
EPSS
0.95%
Windows

Original NVD Description

Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI commands through a localhost HTTP API without authentication and configures the allow_origins setting as a wildcard in both src/winml/modelkit/serve/cli_api.py and src/winml/modelkit/serve/app.py. A malicious website loaded by a user can send cross-origin requests to /v1/cli/build or /v1/cli/config and set the trust_remote_code parameter to true, which is converted to the --trust-remote-code command-line flag without validation. This reaches AutoConfig.from_pretrained with trust_remote_code=True in src/winml/modelkit/loader/_autoconfig.py and imports Python code from an attacker-controlled model repository, resulting in arbitrary code execution as the server user. This issue is fixed in version 0.4.0.