OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-96804

HIGH · CVSS 8.8 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

MLflow's statsmodel flavor, specifically versions 2.1.0 to 3.14.0, is vulnerable due to the absence of the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control in the _load_model() function. This flaw enables remote attackers to execute arbitrary code by exploiting a crafted MLmodel artifact, posing a significant risk to systems utilizing these versions. Organizations using affected versions should prioritize remediation to mitigate potential exploitation risks.

CVE
CVE-2026-96804
Severity
HIGH
CVSS
8.8
EPSS
0.42%

Original NVD Description

MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.