CVE-2024-27134: Lfprojects MLflow

High severity, CVSS 7.0. EPSS: 0.1% chance of exploitation in the next 30 days.

Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when the spark_udf() MLflow API is called.

Affected products

  • Lfprojects MLflow: before 2.16.0 (fixed in 2.16.0)

Published 2024-11-25. Last modified 2026-06-17.