CVE-2025-15381 - CVE House
Back to Database
Status published High CVE-2025-15381

Unauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflow

Vulnerability Description

In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission validators. This allows any authenticated user, including those with `NO_PERMISSIONS` on the experiment, to read trace information and create assessments for traces they should not have access to. This vulnerability impacts confidentiality by exposing trace metadata and integrity by allowing unauthorized creation of assessments. Deployments using `mlflow server --app-name=basic-auth` are affected.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-15381

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

mlflow/mlflow
Vulnerable Versions:
unspecified

Timeline

Official Publish: March 27th, 2026
Last Modified: July 15th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Weaknesses (CWE)