THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3p64-6gvh-82v5 (medium) — MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth

[GHSA] GHSA-3p64-6gvh-82v5 (medium) — MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth

medgithub_advisoriesPublished 2026-08-17

GHSA-3p64-6gvh-82v5 Severity: medium CVE: CVE-2026-69146

MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth

### Summary

When MLflow is deployed with the built-in basic-auth plugin (`--app-name basic-auth`), any authenticated user can inject arbitrary dataset records into another user's run by calling `POST /api/2.0/mlflow/runs/log-inputs`. The `LogInputs` proto handl

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3p64-6gvh-82v5