CVE-2026-96804 | MLflow up to 3.14.0 statsmodel flavor _load_model deserialization
A vulnerability categorized as problematic has been discovered in MLflow up to 3.14.0. Affected by this vulnerability is the function _load_model of the component statsmodel flavor. Such manipulation leads to deserialization.
This vulnerability is documented as CVE-2026-96804. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More