THREAT OPS › Threat News › [GHSA] GHSA-3p64-6gvh-82v5 (medium) — MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
[GHSA] GHSA-3p64-6gvh-82v5 (medium) — MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
GHSA-3p64-6gvh-82v5 Severity: medium CVE: CVE-2026-69146
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
### Summary
When MLflow is deployed with the built-in basic-auth plugin (`--app-name basic-auth`), any authenticated user can inject arbitrary dataset records into another user's run by calling `POST /api/2.0/mlflow/runs/log-inputs`. The `LogInputs` proto handl
Indicators of compromise
- CVE-2026-69146cve
Original source: https://github.com/advisories/GHSA-3p64-6gvh-82v5