Vulnerability PYSEC-2026-3686

High Risk
HIGH RISK
CVSS Score: 8.1
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
1 month ago
August 19, 2026 at 11:56 AM UTC
MLflow: trace API endpoints lack proper authorization validators
2.14.0rc0 - 3.12.0
2.14.0rc0 - 3.12.0

Summary

MLflow: trace API endpoints lack proper authorization validators

Details

In MLflow versions prior to 3.13.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces on experiments they do not have permission to access. The issue arises from the _before_request handler, which does not register authorization validators for trace endpoints, resulting in requests proceeding without validation. This vulnerability can expose sensitive data, destroy audit logs, and allow unauthorized modifications.

Impacted packages

Timeline

Published
1 month ago
August 19, 2026 at 11:56 AM UTC
Fixed (3.13.0rc0)
4 months ago
May 22, 2026 at 03:11 AM UTC
Last Modified
1 month ago
August 19, 2026 at 12:55 PM UTC