# CVE-2026-4137

## Summary

- **CVE ID:** CVE-2026-4137
- **Severity:** HIGH
- **CVSS Score:** 7 (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-378
- **Published:** May 18, 2026
- **Last Modified:** May 19, 2026

## Description

In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` creates temporary directories with world-writable permissions (0o777), and the `_create_model_downloading_tmp_dir()` function in `mlflow/pyfunc/__init__.py` creates directories with group-writable permissions (0o770). These insecure permissions allow local attackers to tamper with model artifacts, such as cloudpickle-serialized Python objects, and achieve arbitrary code execution when the tampered artifacts are deserialized via `cloudpickle.load()`. This vulnerability is particularly critical in environments with shared NFS mounts, such as Databricks, where NFS is enabled by default. The issue is a continuation of the vulnerability class addressed in CVE-2025-10279, which was only partially fixed.

## Affected Products

- mlflow — mlflow/mlflow (unspecified)

## References

- [CNA](https://huntr.com/bounties/648dc30b-76c7-4433-86b8-f43d926fd8d6)
- [CNA](https://github.com/mlflow/mlflow/commit/1dcbb0c2fbd1f446c328830e601ca13a28219b8a)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.19%
- **EPSS Percentile:** 9.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._