{"id":"PYSEC-2026-3686","summary":"MLflow: trace API endpoints lack proper authorization validators","details":"In MLflow versions prior to 3.13.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces on experiments they do not have permission to access. The issue arises from the `_before_request` handler, which does not register authorization validators for trace endpoints, resulting in requests proceeding without validation. This vulnerability can expose sensitive data, destroy audit logs, and allow unauthorized modifications.","aliases":["BIT-mlflow-2026-8147","CVE-2026-8147","GHSA-2cm6-r77w-6g96"],"modified":"2026-08-19T12:55:38.896729948Z","published":"2026-08-19T11:56:24.904399Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8147"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/pull/23014"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/commit/f9b1eb510478570609ef451984a255775aa4b937"},{"type":"PACKAGE","url":"https://github.com/mlflow/mlflow"},{"type":"WEB","url":"https://github.com/mlflow/mlflow/releases/tag/v3.13.0"},{"type":"WEB","url":"https://huntr.com/bounties/b00c3ddd-373e-492f-9bf0-41a28bb21ed5"},{"type":"PACKAGE","url":"https://pypi.org/project/mlflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2cm6-r77w-6g96"}],"affected":[{"package":{"name":"mlflow","ecosystem":"PyPI","purl":"pkg:pypi/mlflow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.14.0rc0"},{"fixed":"3.13.0rc0"}]}],"versions":["2.14.0","2.14.0rc0","2.14.1","2.14.2","2.14.2.dev0","2.14.3","2.15.0","2.15.0rc0","2.15.1","2.16.0","2.16.1","2.16.2","2.17.0","2.17.0rc0","2.17.1","2.17.2","2.18.0","2.18.0rc0","2.19.0","2.19.0rc0","2.20.0","2.20.0rc0","2.20.1","2.20.2","2.20.3","2.20.4","2.21.0","2.21.0rc0","2.21.1","2.21.2","2.21.3","2.22.0","2.22.0rc0","2.22.1","2.22.2","2.22.3","2.22.4","2.22.5","3.0.0","3.0.0rc0","3.0.0rc1","3.0.0rc2","3.0.0rc3","3.0.1","3.1.0","3.1.0rc0","3.1.1","3.1.2","3.1.3","3.1.4","3.10.0","3.10.0rc0","3.10.1","3.11.0","3.11.0rc0","3.11.0rc1","3.11.1","3.12.0","3.12.0rc0","3.2.0","3.2.0rc0","3.3.0","3.3.0rc0","3.3.1","3.3.2","3.4.0","3.4.0rc0","3.5.0","3.5.0rc0","3.5.1","3.6.0","3.6.0rc0","3.7.0","3.7.0rc0","3.8.0","3.8.0rc0","3.8.1","3.9.0","3.9.0rc0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/mlflow/PYSEC-2026-3686.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}