CVE-2026-69146: MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the ml...
Added to the CISA Known Exploited Vulnerabilities catalog on 17 Aug 2026. Vendor: AI/ML. Product: machine learning. CVSS score: 6.5.
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any authenticated user to call POST /api/2.0/mlflow/runs/log-inpu...
Required action: Review and patch if applicable to your AI infrastructure.