{
  "threat_severity" : "Important",
  "public_date" : "2026-05-11T19:02:46Z",
  "bugzilla" : {
    "description" : "mlflow: mlflow: Arbitrary file read via bypassed source path validation",
    "id" : "2469309",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2469309"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-22",
  "details" : [ "A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem. The issue arises when a `CreateModelVersion` request includes the tag `mlflow.prompt.is_prompt`, which bypasses source path validation. This enables an attacker to store an arbitrary local filesystem path as the model version source. The `get_model_version_artifact_handler()` function later uses this source to serve files without verifying the model version's prompt status, leading to a complete confidentiality compromise. This issue is fixed in version 3.10.0.", "A flaw was found in mlflow. An unauthenticated remote attacker can exploit a vulnerability in the `_create_model_version()` handler by including a specific tag, `mlflow.prompt.is_prompt`, in a `CreateModelVersion` request. This bypasses source path validation, allowing the attacker to specify an arbitrary local filesystem path as the model version source. Subsequently, the `get_model_version_artifact_handler()` function serves files from this unverified source, leading to the disclosure of arbitrary files from the server's filesystem and a complete confidentiality compromise." ],
  "statement" : "This Important vulnerability in mlflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem. The flaw exists in the `_create_model_version()` handler, where a specially crafted request with the `mlflow.prompt.is_prompt` tag bypasses source path validation. This enables an attacker to specify an arbitrary local filesystem path, leading to complete confidentiality compromise within Red Hat OpenShift AI environments.",
  "affected_release" : [ {
    "product_name" : "Red Hat OpenShift AI 3.3",
    "release_date" : "2026-07-09T00:00:00Z",
    "advisory" : "RHSA-2026:37275",
    "cpe" : "cpe:/a:redhat:openshift_ai:3.3::el9",
    "package" : "rhoai/odh-training-cuda128-torch29-py312-rhel9:1782991170"
  }, {
    "product_name" : "Red Hat OpenShift AI 3.4",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34456",
    "cpe" : "cpe:/a:redhat:openshift_ai:3.4::el9",
    "package" : "rhoai/odh-th06-cpu-torch210-py312-rhel9:1782135464"
  }, {
    "product_name" : "Red Hat OpenShift AI 3.4",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34456",
    "cpe" : "cpe:/a:redhat:openshift_ai:3.4::el9",
    "package" : "rhoai/odh-th06-cuda130-torch210-py312-rhel9:1782136276"
  }, {
    "product_name" : "Red Hat OpenShift AI 3.4",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34456",
    "cpe" : "cpe:/a:redhat:openshift_ai:3.4::el9",
    "package" : "rhoai/odh-th06-rocm64-torch291-py312-rhel9:1782135346"
  }, {
    "product_name" : "Red Hat OpenShift AI 3.4",
    "release_date" : "2026-07-01T00:00:00Z",
    "advisory" : "RHSA-2026:34456",
    "cpe" : "cpe:/a:redhat:openshift_ai:3.4::el9",
    "package" : "rhoai/odh-training-cuda128-torch29-py312-rhel9:1782132240"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Not affected",
    "package_name" : "rhoai/odh-mlflow-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-2614\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-2614\nhttps://github.com/mlflow/mlflow/commit/6e801f4259d96804c73107315b24cef0f6aa115a\nhttps://huntr.com/bounties/19380271-3fbf-4beb-987e-6fd7069c55e6" ],
  "name" : "CVE-2026-2614",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}