A vulnerability was found in zenml-io zenml up to 0.94.2. It has been declared as critical. The affected element is an unknown function of the component Rate Limiting. Such manipulation of the argument X-Forwarded-For leads to improper access controls.
This vulnerability is referenced as CVE-2026-11922. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.