Medium severity5.4NVD Advisory· Published Sep 16, 2026· Updated Sep 16, 2026
CVE-2026-92568
CVE-2026-92568
Description
MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to internal addresses. Attackers can update a run with a malicious webhook notification that executes when the run reaches a terminal state, enabling requests to internal services, Kubernetes APIs, or cloud metadata endpoints from within the cluster.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.