What is CVE-2026-68772?
CVE-2026-68772 is a remote code execution vulnerability in the CloudpickleMaterializer component of ZenML 0.94.6. An attacker with write access to a shared artifact store can execute arbitrary code by replacing a stored artifact.pkl file with a malicious pickle file. Users are advised to immediately upgrade to a patched version.
Azərbaycanca: CVE-2026-68772 ZenML 0.94.6-da CloudpickleMaterializer komponentində aşkarlanan remote code execution zəifliyidir. Paylaşılan artifact store-a yazma icazəsi olan hücumçu, artifact.pkl faylını zərərli pickle ilə əvəz edərək ixtiyari kod icra edə bilər. İstifadəçilərə dərhal ZenML versiyasını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
In which component of ZenML was CVE-2026-68772 discovered?
The vulnerability was discovered in the CloudpickleMaterializer component of ZenML version 0.94.6.
How can an attacker exploit CVE-2026-68772?
An attacker with write access to a shared artifact store can execute arbitrary code by replacing a stored artifact.pkl file with a malicious pickle file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.