Authorization Bypass in mlflow/mlflow
Published Jul 2, 2026
8.1
HIGHCVSS 3.1
EPSS 0.55%
Description
In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces on experiments they do not have permission to access. The issue arises from the `_before_request` handler, which does not register authorization validators for trace endpoints, resulting in requests proceeding without validation. This vulnerability can expose sensitive data, destroy audit logs, and allow unauthorized modifications.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<3.14.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mlflow | Mlflow/mlflow | n/a |
|
- < 3.14.0
No data.
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mlflow-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cpu-torch210-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cuda130-torch210-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-rocm64-torch291-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-training-cuda128-torch29-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mlflow-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch210-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cuda130-torch210-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-rocm64-torch291-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-training-cuda128-torch29-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Important flaw in MLflow, as deployed in Red Hat OpenShift AI, allows an authenticated user to bypass experiment-level authorization controls on trace API endpoints. This enables unauthorized access, modification, and deletion of sensitive trace data, impacting the confidentiality and integrity of machine learning experiment results within the platform. The vulnerability specifically affects the `rhoai/odh-mlflow-rhel9` component.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-8147 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2496410 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41257 Advisory
- https://github.com/advisories/GHSA-2cm6-r77w-6g96 Advisory
- https://github.com/mlflow/mlflow/commit/f9b1eb510478570609ef451984a255775aa4b937 Patch
- https://github.com/mlflow/mlflow/pull/23014
- https://github.com/mlflow/mlflow/releases/tag/v3.13.0
- https://huntr.com/bounties/b00c3ddd-373e-492f-9bf0-41a28bb21ed5 exploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-8147
- https://www.cve.org/CVERecord?id=CVE-2026-8147
Change history (0)
No recorded changes yet.