CVE-2026-69146Patch

MEDIUMCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any authenticated user to call POST /api/2.0/mlflow/runs/log-inputs for another user's run_id and inject attacker-controlled DatasetInput records into the dataset_inputs lineage metadata without UPDATE permission. This issue is fixed in version 3.15.0.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-08-18); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-18: 1Mentions · 2026-08-19: 1Mentions · 2026-08-20: 1Active Exploitation · 2026-08-20: 1Patch / Workaround · 2026-08-18: 1Patch / Workaround · 2026-08-20: 1Technical Details · 2026-08-18: 1Technical Details · 2026-08-19: 1Technical Details · 2026-08-20: 108-1808-1908-20
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-181
Patch1
2026-08-191
Disclosure1
2026-08-201
Patch1
Full discourse3 posts
  • Checkmarx Zero@CheckmarxZero
    Patch

    🚨 If you're running MLflow, stop and read this. CVE-2026-64849 is a critical unauthenticated SSRF discovered in the default MLflow Tracking server. It lets attackers reach internal services and potentially steal sensitive data without requiring a login, and it's already being exploited in the wild. We recommend upgrading to version 3.15.0 as it also fixes two additional flaws affecting MLflow, CVE-2026-69148 and CVE-2026-69146. More details: https://devhub.checkmarx.com/cve-details/CVE-2026-64849/

    Post summary

    The advisory warns of an actively exploited unauthenticated SSRF in MLflow and urges users to upgrade to version 3.15.0 to apply the patch.

    0002091
    247 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 MLflow, Authorization Bypass, #CVE-2026-69146 (MEDIUM) -DC-Aug2026-1586 https://dailycve.com/mlflow-authorization-bypass-cve-2026-69146-medium-dc-aug2026-1586/

    Post summary

    A new medium‑severity authorization bypass vulnerability, CVE‑2026‑69146, has been disclosed in MLflow. Further technical details can be found in the linked dailycve article.

    0000155
    229 followersView on X
  • iSECTECH@isectech_
    Patch

    MLflow CVE-2026-69146 shows why lineage is security data: an authenticated user could inject dataset records into another user’s run. Upgrade to 3.15.0, monitor log-inputs, and independently verify audit evidence. https://github.com/mlflow/mlflow/security/advisories/GHSA-3p64-6gvh-82v5

    Post summary

    The advisory highlights CVE-2026-69146, which allows authenticated users to inject dataset records into other users’ runs, and recommends upgrading to MLflow 3.15.0 to mitigate the issue.

    0000029
    86 followersView on X

Explore more