
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15381 is an authorization bypass vulnerability in mlflow/mlflow affecting the basic-auth application mode. When the server is launched with --app-name=basic-auth, tracing and assessment endpoints lack permission validators, allowing any authenticated user — including those explicitly granted NO_PERMISSIONS on an experiment — to read trace metadata and create assessments for traces they should not have access to. The vulnerability was published on March 27, 2026, and is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). It carries a CVSS v3.1 base score of 7.1 (High) per NVD, and 8.1 (High) per the ENISA/huntr scoring (Red Hat Advisory, huntr Bounty).
The root cause is a missing authorization check (CWE-200) on tracing and assessment API endpoints within MLflow's basic-auth Flask application. When MLflow is started with mlflow server --app-name=basic-auth, the basic-auth middleware enforces permission validators on most endpoints, but tracing (e.g., trace read/list) and assessment (e.g., assessment creation) endpoints are not covered by these validators. As a result, any authenticated user — regardless of their assigned permission level on the experiment — can send HTTP requests directly to these endpoints and successfully retrieve trace metadata or submit assessments. No special privileges beyond a valid authentication credential are required (huntr Bounty, Red Hat Advisory).
Successful exploitation impacts both confidentiality and integrity. An attacker with any valid MLflow account — even one explicitly denied access to an experiment — can read sensitive trace metadata (e.g., model inputs, outputs, parameters, and run context) from experiments they are not authorized to view, and can inject unauthorized assessments into those traces, potentially corrupting evaluation records or misleading model governance workflows. Availability is not impacted. The scope is limited to the MLflow server instance, but in multi-tenant or shared MLflow deployments, this could expose proprietary ML pipeline data across organizational boundaries (Red Hat Advisory, huntr Bounty).
No confirmed in-the-wild exploitation has been observed, and no functional proof-of-concept exploit code is publicly available as of the time of reporting. The EPSS score is 0.0001 (very low probability of exploitation in the near term), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The huntr bounty page is referenced as the disclosure source, but its content was not publicly accessible for detailed PoC review (huntr Bounty, Red Hat Advisory).
--app-name=basic-auth enabled, accessible over the network (e.g., via Shodan, internal network scanning, or known deployment inventories).NO_PERMISSIONS on the target experiment. This could be a low-privilege or guest account.GET /api/2.0/mlflow/experiments/list) to identify experiment IDs of interest, including those the attacker's account has no permissions on.GET /api/2.0/mlflow/traces?experiment_id=<target_id>) to retrieve trace metadata from restricted experiments./api/2.0/mlflow/assessments) with a payload referencing a trace ID from the restricted experiment, successfully injecting assessments without authorization (huntr Bounty)./api/2.0/mlflow/traces or similar tracing endpoints from user accounts with NO_PERMISSIONS or low-privilege roles; HTTP POST requests to /api/2.0/mlflow/assessments from accounts not expected to create assessments.No patched version of MLflow has been confirmed as available at the time of disclosure. Recommended mitigations include: (1) Disable basic-auth if not strictly required, reverting to a deployment without --app-name=basic-auth; (2) Restrict network access to the MLflow server to trusted networks or VPNs only, reducing the attack surface; (3) Audit existing trace data and assessments for signs of unauthorized access or modification; (4) Monitor for a patched MLflow release that implements permission validators on tracing and assessment endpoints, and upgrade promptly upon availability (Red Hat Advisory, huntr Bounty).
Red Hat has acknowledged the vulnerability and published a security advisory tracking it. The issue was reported through the huntr bug bounty platform, which coordinates responsible disclosure for open-source AI/ML projects. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified at this time (Red Hat Advisory, huntr Bounty).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."