PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15381 mlflow CVE debrief

CVE-2025-15381 is a high-severity vulnerability in the mlflow/mlflow project. When the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission validators. This allows any authenticated user, including those with `NO_PERMISSIONS` on the experiment, to read trace information and create assessments for traces they should not have access to. The vulnerability impacts confidentiality by exposing trace metadata and integrity by allowing unauthorized creation of assessments. Deployments using `mlflow server --app-name=basic-auth` are affected. Users should update to a patched version as soon as possible.

Vendor
mlflow
Product
mlflow/mlflow
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-27
Original CVE updated
2026-07-15
Advisory published
2026-03-27
Advisory updated
2026-07-15

Who should care

Users of mlflow/mlflow who have enabled the `basic-auth` app should be aware of this vulnerability. This includes anyone using mlflow/mlflow for tracing and assessment, especially in environments where multiple users have access to the system. Security teams should prioritize patching or mitigating this vulnerability to prevent unauthorized access to sensitive information.

Technical summary

The vulnerability exists in the mlflow/mlflow project when the `basic-auth` app is enabled. Tracing and assessment endpoints do not have proper permission validation, allowing authenticated users to access and create assessments for traces they should not have access to. This is due to a lack of permission checks on these endpoints. The vulnerability has a CVSS score of 7.1 and is considered high severity.

Defensive priority

High priority should be given to patching or mitigating this vulnerability. As the vulnerability allows unauthorized access to sensitive information and creation of assessments, defenders should act quickly to protect their environments.

Recommended defensive actions

  • Update to a patched version of mlflow/mlflow as soon as available.
  • Disable the `basic-auth` app if not required.
  • Implement additional access controls or permission checks for tracing and assessment endpoints.
  • Monitor for suspicious activity on tracing and assessment endpoints.
  • Review and update user permissions to ensure least privilege access.

Evidence notes

The vulnerability was reported by [email protected] and is documented in the NVD and CVE records. Multiple sources, including Red Hat, have provided additional information and references. However, the exact scope of affected systems and users is not fully clear from the available information.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-15381 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-15381

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-15381 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15381

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://huntr.com/bounties/149fb2f9-ef4b-4136-a25c-20563451904c

    [email protected] - Exploit, Third Party Advisory

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2025-15381

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15381.json

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.