Vulnerability Description
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any authenticated user to call POST /api/2.0/mlflow/runs/log-inputs for another user's run_id and inject attacker-controlled DatasetInput records into the dataset_inputs lineage metadata without UPDATE permission. This issue is fixed in version 3.15.0.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/mlflow/mlflow/commit/5c34aec5669e2386b38b5ee0855cd61174e27693
- https://github.com/mlflow/mlflow/pull/24291
- https://github.com/mlflow/mlflow/releases/tag/v3.15.0
- https://github.com/mlflow/mlflow/security/advisories/GHSA-3p64-6gvh-82v5
- https://github.com/mlflow/mlflow/security/advisories/GHSA-3p64-6gvh-82v5
FAQ
What is CVE-2026-69146?
CVE-2026-69146 is a vulnerability with a CVSS score of 6.5 (MEDIUM). MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflo...
How severe is CVE-2026-69146?
CVE-2026-69146 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-69146?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.