Skip to main content
← Back to Demos
Malware intermediate · 15 min

Cloud Credential Theft via MLflow SSRF — Adaptive Sandbox Flags Metadata-Service Credential Probing (CVE-2026-64849)

The unauthenticated SSRF in MLflow tracked as CVE-2026-64849 (CVSS 9.3, affects versions < 3.15.0) lets attackers reach internal services by abusing how the model-registry webhook handles HTTP redirects. Within hours of the CVE being assigned on August 17, 2026, watchTowr observed live scanning that chained the flaw to reach cloud metadata endpoints (AWS IMDSv1, GCP metadata) and extract cloud credentials and secrets — a classic 'Cloud Instance Metadata API' (T1522) credential-theft path where a public-facing app becomes a relay that hands the attacker the instance's IAM tokens. This demo reproduces the credential-probing behavior safely: the sample writes a local demo credential file (user=demo, password=demo) as a stand-in for an IMDS token fetch, then opens Calculator as its only visible impact — nothing real is queried or exfiltrated. Adaptive Sandbox detonates the sample in an isolated Windows environment, observes the credential-store probing sequence, and reports the suspicious behavior with behavioral indicators before any real tokens could be touched.

Attack Technique

SSRF chained to cloud metadata credential theft (T1522)

MITRE ATT&CK

T1522 ↗

Platforms

linux

File Types

.cmd.sh

MetaDefender Capabilities

Adaptive Sandbox

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---