CVE-2026-8147
published 2026-07-02CVE-2026-8147: In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any…
PriorityP358high8.1CVSS 3.0
AVNACLPRLUINSUCHIHAN
EPSS
0.55%
44.8th percentile
In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces on experiments they do not have permission to access. The issue arises from the `_before_request` handler, which does not register authorization validators for trace endpoints, resulting in requests proceeding without validation. This vulnerability can expose sensitive data, destroy audit logs, and allow unauthorized modifications.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lfprojects | mlflow | < 3.14.0 | 3.14.0 |
| lfprojects | mlflow | >= 2.14.0rc0 < 3.13.0rc0 | 3.13.0rc0 |
| mlflow | mlflow_mlflow | >= unspecified < 3.14.0 | 3.14.0 |
| rhoai | odh-mlflow-rhel9 | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
MLflow: trace API endpoints lack proper authorization validators
ghsa·2026-07-02
CVE-2026-8147 [HIGH] CWE-284 MLflow: trace API endpoints lack proper authorization validators
MLflow: trace API endpoints lack proper authorization validators
In MLflow versions prior to 3.13.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces on experiments they do not have permission to access. The issue arises from the `_before_request` handler, which does not register authorization validators for trace endpoints, resulting in requests proceeding without validation. This vulnerability can expose sensitive data, destroy audit logs, and allow unauthorized modifications.
GHSA
In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators.
ghsa_unreviewed·2026-07-02
CVE-2026-8147 [HIGH] CWE-284 In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators.
In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces on experiments they do not have permission to access. The issue arises from the `_before_request` handler, which does not register authorization validators for trace endpoints, resulting in requests proceeding without validation. This vulnerability can expose sensitive data, destroy audit logs, and allow unauthorized modifications.
Red Hat
mlflow: MLflow: Unauthorized access to trace data due to missing authorization validation
vendor_redhat·2026-07-02·CVSS 8.1
CVE-2026-8147 [HIGH] CWE-425 mlflow: MLflow: Unauthorized access to trace data due to missing authorization validation
mlflow: MLflow: Unauthorized access to trace data due to missing authorization validation
In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces on experiments they do not have permission to access. The issue arises from the `_before_request` handler, which does not register authorization validators for trace endpoints, resulting in requests proceeding without validation. This vulnerability can expose sensitive data, destroy audit logs, and allow unauthorized modifications.
A flaw was found in MLflow. When authentication is enabled, any authentica
No detection rules found.
No public exploits indexed.
2026-07-02
Published