CVE-2026-69148
published 2026-08-17CVE-2026-69148: MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a…
PriorityP342high7.1CVSS 3.1
AVNACLPRLUINSUCHILAN
EPSS
0.37%
28.2th percentile
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in mlflow/server/handlers.py verifies only path containment, allowing authenticated users to create a model version that references another user's artifact directory and read files through GET /model-versions/get-artifact without the required READ permission. This issue is fixed in version 3.15.0.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lfprojects | mlflow | >= 0 < 3.15.0 | 3.15.0 |
| mlflow | mlflow | < 3.15.0 | 3.15.0 |
| rhoai | odh-mlflow-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-pytorch-rocm-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-tensorflow-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-tensorflow-rocm-py312-rhel9 | — | — |
| rhoai | odh-th-torch-cpu-py312-rhel9 | — | — |
| rhoai | odh-th-torch-cuda-py312-rhel9 | — | — |
| rhoai | odh-th-torch-rocm-py312-rhel9 | — | — |
| rhoai | odh-th06-cpu-torch210-py312-rhel9 | — | — |
| rhoai | odh-th06-cuda130-torch210-py312-rhel9 | — | — |
| rhoai | odh-th06-rocm64-torch291-py312-rhel9 | — | — |
| rhoai | odh-training-cuda128-torch29-py312-rhel9 | — | — |
| rhoai | odh-workbench-codeserver-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-rocm-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-tensorflow-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-tensorflow-rocm-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-trustyai-cpu-py312-rhel9 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
MLflow up to 3.14.x Model Version Creation handlers.py _validate_source_run/_validate_source_model run_id/model_id permission
vuldb·2026-08-17·CVSS 7.1
CVE-2026-69148 [HIGH] MLflow up to 3.14.x Model Version Creation handlers.py _validate_source_run/_validate_source_model run_id/model_id permission
A vulnerability was found in MLflow up to 3.14.x. It has been rated as problematic. This issue affects the function _validate_source_run/_validate_source_model of the file mlflow/server/handlers.py of the component Model Version Creation. Performing a manipulation of the argument run_id/model_id results in permission issues.
This vulnerability is identified as CVE-2026-69148. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
GHSA
MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
ghsa·2026-08-17
CVE-2026-69148 [HIGH] CWE-862 MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
### Summary
The `_validate_source_run` and `_validate_source_model` functions in `mlflow/server/handlers.py` verify that a model version source path is within the artifact directory of a specified run or logged model, but do not check whether the caller has READ permission on that run or model. An authenticated MLflow user can therefore reference another user's run_id in `CreateModelVersion`, creating a model version whose artifact URI points at the victim's artifact directory. If the calling user has MANAGE permission on the registered model (which they do after creation), they can then read arbitrary files from the victim's artifact directory via `GET /model-versions/get-artifact`, bypassin
Red Hat
mlflow: MLflow: Information disclosure via insufficient validation in CreateModelVersion
vendor_redhat·2026-08-17·CVSS 7.1
CVE-2026-69148 [HIGH] CWE-22 mlflow: MLflow: Information disclosure via insufficient validation in CreateModelVersion
mlflow: MLflow: Information disclosure via insufficient validation in CreateModelVersion
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in mlflow/server/handlers.py verifies only path containment, allowing authenticated users to create a model version that references another user's artifact directory and read files through GET /model-versions/get-artifact without the required READ permission. This issue is fixed in version 3.15.0.
A flaw was found in MLflow, an open-source AI engineering platform. Insufficient validation in the `CreateModelVersion` function allows an authenticated user to create a model
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/mlflow/mlflow/commit/4bb7474771c3be808cd9e129defef9305f2869behttps://github.com/mlflow/mlflow/pull/24293https://github.com/mlflow/mlflow/releases/tag/v3.15.0https://github.com/mlflow/mlflow/security/advisories/GHSA-gqch-g4w5-7qcwhttps://github.com/mlflow/mlflow/security/advisories/GHSA-gqch-g4w5-7qcw
2026-08-17
Published