CVE-2025-15381: 
MLflow vulnerability analysis and mitigation

Overview

CVE-2025-15381 is an authorization bypass vulnerability in mlflow/mlflow affecting the basic-auth application mode. When the server is launched with --app-name=basic-auth, tracing and assessment endpoints lack permission validators, allowing any authenticated user — including those explicitly granted NO_PERMISSIONS on an experiment — to read trace metadata and create assessments for traces they should not have access to. The vulnerability was published on March 27, 2026, and is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). It carries a CVSS v3.1 base score of 7.1 (High) per NVD, and 8.1 (High) per the ENISA/huntr scoring (Red Hat Advisory, huntr Bounty).

Technical details

The root cause is a missing authorization check (CWE-200) on tracing and assessment API endpoints within MLflow's basic-auth Flask application. When MLflow is started with mlflow server --app-name=basic-auth, the basic-auth middleware enforces permission validators on most endpoints, but tracing (e.g., trace read/list) and assessment (e.g., assessment creation) endpoints are not covered by these validators. As a result, any authenticated user — regardless of their assigned permission level on the experiment — can send HTTP requests directly to these endpoints and successfully retrieve trace metadata or submit assessments. No special privileges beyond a valid authentication credential are required (huntr Bounty, Red Hat Advisory).

Impact

Successful exploitation impacts both confidentiality and integrity. An attacker with any valid MLflow account — even one explicitly denied access to an experiment — can read sensitive trace metadata (e.g., model inputs, outputs, parameters, and run context) from experiments they are not authorized to view, and can inject unauthorized assessments into those traces, potentially corrupting evaluation records or misleading model governance workflows. Availability is not impacted. The scope is limited to the MLflow server instance, but in multi-tenant or shared MLflow deployments, this could expose proprietary ML pipeline data across organizational boundaries (Red Hat Advisory, huntr Bounty).

Exploitability

No confirmed in-the-wild exploitation has been observed, and no functional proof-of-concept exploit code is publicly available as of the time of reporting. The EPSS score is 0.0001 (very low probability of exploitation in the near term), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The huntr bounty page is referenced as the disclosure source, but its content was not publicly accessible for detailed PoC review (huntr Bounty, Red Hat Advisory).

Exploitation steps

  1. Reconnaissance: Identify an MLflow server instance running with --app-name=basic-auth enabled, accessible over the network (e.g., via Shodan, internal network scanning, or known deployment inventories).
  2. Obtain credentials: Acquire any valid MLflow user account — even one with NO_PERMISSIONS on the target experiment. This could be a low-privilege or guest account.
  3. Authenticate: Log in to the MLflow server using the obtained credentials to obtain a valid session token or basic-auth header.
  4. Enumerate experiments: Use the MLflow REST API (e.g., GET /api/2.0/mlflow/experiments/list) to identify experiment IDs of interest, including those the attacker's account has no permissions on.
  5. Access trace endpoints: Send authenticated HTTP requests to unprotected tracing endpoints (e.g., GET /api/2.0/mlflow/traces?experiment_id=<target_id>) to retrieve trace metadata from restricted experiments.
  6. Create unauthorized assessments: Send authenticated HTTP POST requests to assessment endpoints (e.g., /api/2.0/mlflow/assessments) with a payload referencing a trace ID from the restricted experiment, successfully injecting assessments without authorization (huntr Bounty).

Indicators of compromise

  • Network: Unusual HTTP GET requests to /api/2.0/mlflow/traces or similar tracing endpoints from user accounts with NO_PERMISSIONS or low-privilege roles; HTTP POST requests to /api/2.0/mlflow/assessments from accounts not expected to create assessments.
  • Logs: MLflow access logs showing authenticated requests to tracing/assessment endpoints by users who are not authorized for the associated experiment; repeated cross-experiment trace queries from a single low-privilege account.
  • Application Behavior: Unexpected assessments appearing on traces in experiments where the creating user has no assigned permissions; anomalous volume of trace read operations from non-admin accounts.

Mitigation and workarounds

No patched version of MLflow has been confirmed as available at the time of disclosure. Recommended mitigations include: (1) Disable basic-auth if not strictly required, reverting to a deployment without --app-name=basic-auth; (2) Restrict network access to the MLflow server to trusted networks or VPNs only, reducing the attack surface; (3) Audit existing trace data and assessments for signs of unauthorized access or modification; (4) Monitor for a patched MLflow release that implements permission validators on tracing and assessment endpoints, and upgrade promptly upon availability (Red Hat Advisory, huntr Bounty).

Community reactions

Red Hat has acknowledged the vulnerability and published a security advisory tracking it. The issue was reported through the huntr bug bounty platform, which coordinates responsible disclosure for open-source AI/ML projects. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified at this time (Red Hat Advisory, huntr Bounty).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related MLflow vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64849CRITICAL9.3
  • NixOS logoNixOS
  • mlflow
YesYesAug 17, 2026
GHSA-gqvg-gmmx-x4hmHIGH8.8
  • MLflow logoMLflow
  • mlflow
NoYesSep 01, 2026
CVE-2026-8147HIGH8.1
  • NixOS logoNixOS
  • mlflow
NoYesJul 02, 2026
CVE-2026-71211HIGH7.1
  • Wolfi logoWolfi
  • mlflow
NoYesAug 05, 2026
CVE-2026-10803LOW1.1
  • NixOS logoNixOS
  • mlflow
NoYesJun 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management