MLflow latest version contains an authentication bypass caused by unprotected FastAPI job endpoints under /ajax-api/3.0/jobs/* when basic-auth is enabled, letting unauthenticated network clients submit and manage jobs, exploit requires job execution enabled and allowlisted job functions.
id: CVE-2026-0545
info:
name: MLflow Job API - Authentication Bypass
author: DhiyaneshDk
seve
...