CVE-2026-90614
A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument s3_key_str causes deserialization. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
- EPSS probability
- 0.25%
- CWE
- CWE-502, CWE-20
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- FedML-AI FedML
- FedML-AI FedML
- FedML-AI FedML
- FedML-AI FedML
- FedML-AI FedML
- FedML-AI FedML
- FedML-AI FedML
Weakness type
Related vulnerabilities
- CVE-2026-87719 — Deserialization of Untrusted Data in GitLab
- CVE-2026-72649 — Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution
- CVE-2026-82222 — WordPress GiveWP plugin <= 4.16.7.1 - Remote Code Execution (RCE) vulnerability
- CVE-2026-70416 — Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthentica
- CVE-2026-17061 — Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026
- CVE-2026-4703 — WS Form LITE <= 1.10.80 - Unauthenticated PHP Object Injection via Form Submission
- CVE-2026-20307 — Cisco Identity Services Engine Remote Code Execution Vulnerability
- CVE-2026-12650 — A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated