PT-2026-28274 · Mlflow · Mlflow
Published
2026-03-27
·
Updated
2026-03-27
·
CVE-2025-15381
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
mlflow/mlflow (affected versions not specified)
Description
When the
basic-auth application is enabled, tracing and assessment endpoints are not protected by permission validators. This allows any authenticated user, even those with NO PERMISSIONS on an experiment, to read trace information and create assessments for traces they should not have access to. This impacts confidentiality by exposing trace metadata and integrity by allowing unauthorized creation of assessments. The issue affects deployments using mlflow server --app-name=basic-auth. The vulnerable endpoints are tracing and assessment endpoints. The NO PERMISSIONS role is a factor in the exploitation of this issue.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mlflow