CVE-2026-69146
published 2026-08-17CVE-2026-69146: MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent…
PriorityP340medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.39%
30.5th percentile
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any authenticated user to call POST /api/2.0/mlflow/runs/log-inputs for another user's run_id and inject attacker-controlled DatasetInput records into the dataset_inputs lineage metadata without UPDATE permission. This issue is fixed in version 3.15.0.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lfprojects | mlflow | >= 0 < 3.15.0 | 3.15.0 |
| mlflow | mlflow | < 3.15.0 | 3.15.0 |
| rhoai | odh-mlflow-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-rocm-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-tensorflow-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-tensorflow-rocm-py312-rhel9 | — | — |
| rhoai | odh-th-torch-cpu-py312-rhel9 | — | — |
| rhoai | odh-th-torch-cuda-py312-rhel9 | — | — |
| rhoai | odh-th-torch-rocm-py312-rhel9 | — | — |
| rhoai | odh-th06-cpu-torch210-py312-rhel9 | — | — |
| rhoai | odh-th06-cuda130-torch210-py312-rhel9 | — | — |
| rhoai | odh-th06-rocm64-torch291-py312-rhel9 | — | — |
| rhoai | odh-training-cuda128-torch29-py312-rhel9 | — | — |
| rhoai | odh-workbench-codeserver-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-rocm-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-tensorflow-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-tensorflow-rocm-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-trustyai-cpu-py312-rhel9 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
ghsa·2026-08-17
CVE-2026-69146 [MEDIUM] CWE-862 MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
### Summary
When MLflow is deployed with the built-in basic-auth plugin (`--app-name basic-auth`), any authenticated user can inject arbitrary dataset records into another user's run by calling `POST /api/2.0/mlflow/runs/log-inputs`. The `LogInputs` proto handler is absent from the `BEFORE_REQUEST_HANDLERS` map in `mlflow/server/auth/__init__.py`, so the before-request hook skips authorization entirely and the request succeeds. Standard write endpoints on the same run -- such as `POST /api/2.0/mlflow/runs/log-metric` -- correctly return HTTP 403.
### Details
MLflow's basic-auth app gates every HTTP handler through a before-request hook (`_before_request`) that looks up the relevant permission validator in `B
VulDB
MLflow up to 3.14.x LogInputs mlflow/server/auth privileges management
vuldb·2026-08-17·CVSS 6.5
CVE-2026-69146 [MEDIUM] MLflow up to 3.14.x LogInputs mlflow/server/auth privileges management
A vulnerability was found in MLflow up to 3.14.x. It has been declared as problematic. This vulnerability affects unknown code of the file mlflow/server/auth of the component LogInputs. Such manipulation leads to improper privilege management.
This vulnerability is referenced as CVE-2026-69146. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
Red Hat
mlflow: MLflow: Unauthorized data modification via LogInputs endpoint authorization bypass
vendor_redhat·2026-08-17·CVSS 6.5
CVE-2026-69146 [MEDIUM] CWE-639 mlflow: MLflow: Unauthorized data modification via LogInputs endpoint authorization bypass
mlflow: MLflow: Unauthorized data modification via LogInputs endpoint authorization bypass
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any authenticated user to call POST /api/2.0/mlflow/runs/log-inputs for another user's run_id and inject attacker-controlled DatasetInput records into the dataset_inputs lineage metadata without UPDATE permission. This issue is fixed in version 3.15.0.
A flaw was found in MLflow, an open-source AI engineering platform. An authenticated user could bypass authorization controls by sending requests to the LogInputs endpoint for another user's data. This allowed the user to
No detection rules found.
No public exploits indexed.
https://github.com/mlflow/mlflow/commit/5c34aec5669e2386b38b5ee0855cd61174e27693https://github.com/mlflow/mlflow/pull/24291https://github.com/mlflow/mlflow/releases/tag/v3.15.0https://github.com/mlflow/mlflow/security/advisories/GHSA-3p64-6gvh-82v5https://github.com/mlflow/mlflow/security/advisories/GHSA-3p64-6gvh-82v5
2026-08-17
Published