CVE-2026-69146: MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the ml...

Added to the CISA Known Exploited Vulnerabilities catalog on 17 Aug 2026. Vendor: AI/ML. Product: machine learning. CVSS score: 6.5.

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any authenticated user to call POST /api/2.0/mlflow/runs/log-inpu...

Required action: Review and patch if applicable to your AI infrastructure.