Executive brief
MLflow is an open-source platform used by data scientists to manage the machine learning lifecycle, including experiment tracking and model deployment. A security flaw allows unauthorized users to bypass login requirements when the server is configured with basic authentication. This could allow an attacker to remotely submit or cancel machine learning jobs, view sensitive results, and corrupt experiment data, potentially disrupting research and development operations.
Technical details
An authentication bypass exists in MLflow versions prior to 3.11.0 due to an architectural mismatch between Flask and FastAPI authentication mechanisms. When MLflow is served via uvicorn (ASGI) with '--app-name basic-auth', the FastAPI permission middleware incorrectly restricts authentication enforcement to '/gateway/' routes only. The '_find_fastapi_validator()' function fails to validate other paths, leaving the Job API ('/ajax-api/3.0/jobs/*') and OpenTelemetry trace ingestion API ('/v1/traces') unprotected. A remote, unauthenticated attacker can exploit this to perform administrative actions such as job submission, cancellation, and data injection. The issue is resolved in version 3.11.0 (noting some documentation mentions 3.10.0, the package metadata specifies 3.11.0).
Affected products
- MLflow MLflow < 3.11.0
Timeline
- 2026-05-15: advisory: Initial disclosure via GitHub Advisory and NVD
- 2026-05-21: other: Advisory updated and reviewed