PyPI: mlflow
CVE-2026-3198
Safety vulnerability ID: SFTY-20260602-18708
Affected versions of the MLflow package are vulnerable to Improper Access Control due to missing authorization checks. The `BEFORE_REQUEST_HANDLERS` dictionary in `mlflow/server/auth/__init__.py` lacks entries for `ListGatewaySecretInfos`, `ListGatewayEndpoints`, and `ListGatewayModelDefinitions`, resulting in insufficient enforcement of access controls. An attacker can exploit this vulnerability by authenticating as any user and enumerating all gateway secrets, endpoints, and model definitions, thereby gaining access to sensitive information such as API keys, endpoint configurations, and proprietary model definitions.
Overview
MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions
Advisory
mlflow – Improper Access Control
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20260602-18708/CVE-2026-3198
- https://nvd.nist.gov/vuln/detail/CVE-2026-3198
- https://huntr.com/bounties/e57db731-97d3-40c3-a429-831ee959807f
- https://github.com/mlflow/mlflow/commit/6989066af33fdcb03588fd71a1a67f8fc5ef12c9
- https://github.com/advisories/GHSA-r5m9-wm49-959f
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
