
🚨 HIGH - MLflow Trace API authorization bypass (CVE-2026-8147) MLflow with authentication enabled is vulnerable due to missing authorization checks on trace API endpoints, impacting the tracing component used to store and retrieve experiment traces. The root cause is improper authorization validation (access control failure) that fails to enforce experiment-level permissions on trace operations. An attacker only needs a valid authenticated MLflow account to call the trace endpoints directly and bypass experiment access controls to read, delete, or modify traces belonging to other experiments. Exploitation can lead to sensitive data exposure in traces, tampering with experiment telemetry, and deletion of trace/audit artifacts that undermines incident response and compliance. 👉 Affected: mlflow < 3.14.0 (auth enabled) | Upgrade to 3.14.0
Post summary
MLflow’s trace API allows authenticated users to bypass experiment-level access controls, exposing or allowing modification of traces; upgrading to version 3.14.0 resolves the vulnerability.
