Vulnerability record · CVE-2026-8147 · published 2 July 2026
CVE-2026-8147: Lfprojects mlflow improper access control vulnerability
Lfprojects · Mlflow
In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces on experiments they do not have permission to access. The issue arises from the `_before_request` handler, which does not register authorization validators for trace endpoints, resulting in requests proceeding without validation. This vulnerability can expose sensitive data, destroy audit logs, and allow unauthorized modifications.
Description
In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces on experiments they do not have permission to access. The issue arises from the `_before_request` handler, which does not register authorization validators for trace endpoints, resulting in requests proceeding without validation. This vulnerability can expose sensitive data, destroy audit logs, and allow unauthorized modifications.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/mlflow/mlflow/commit/f9b1eb510478570609ef451984a255775aa4b937 | Patch |
| https://huntr.com/bounties/b00c3ddd-373e-492f-9bf0-41a28bb21ed5 | ExploitThird Party Advisory |
| https://huntr.com/bounties/b00c3ddd-373e-492f-9bf0-41a28bb21ed5 | ExploitThird Party Advisory |
Track CVE-2026-8147 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-8147), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.