---
format: "aidr-story-markdown/v1"
id: "d0f89d4413f6d24564735a640b812e7c98ede17ab304ddf3428fb430232a263b"
canonical_url: "https://aidr.today/d0f89d44?lang=en"
title: "Attackers Exploit MLflow Flaw CVE-2026-64849 to Steal Cloud Secrets Hours After Release"
lang: "en"
requested_lang: "en"
available_langs: ["en","vi"]
translation_fallback: null
fallback_fields: []
published_at: "2026-08-18T18:59:33.000Z"
category: "Infra"
topics: ["mlflow","security","infra"]
source_urls: ["https://huggingnews.com/cybersecurity/attackers-exploit-mlflow-flaw-cve-2026-64849-to-steal-cloud-secrets-hour-27543b25"]
summary: "Researchers at watchTowr observed attackers targeting cloud-hosted MLflow systems to extract credentials and secrets using an unauthenticated server-side reque…"
---

# Attackers Exploit MLflow Flaw CVE\-2026\-64849 to Steal Cloud Secrets Hours After Release

> [Open the canonical story](<https://aidr.today/d0f89d44?lang=en>)

**Published:** 2026-08-18T18:59:33.000Z
**Category:** Infra
**Topics:** mlflow, security, infra

## Summary

Researchers at watchTowr observed attackers targeting cloud\-hosted MLflow systems to extract credentials and secrets using an unauthenticated server\-side reque…

## Sources

- [Story source](<https://huggingnews.com/cybersecurity/attackers-exploit-mlflow-flaw-cve-2026-64849-to-steal-cloud-secrets-hour-27543b25>)

