vulns.co
/
GKData.io MCP

Tachyon · 1 min read

MLflow: authorization must survive alternate resource interfaces

Tachyon’s 2026 account of CVE-2025-14297 describes resource permissions depending on incomplete interface registration. Authentication could succeed while a missing authorization mapping permitted resource access. The researcher demonstrates restricted artifact reads and describes unauthorized writes and metadata access; the maintainer’s artifact-interface change corroborates a concrete enforcement gap.

Open the reference Research PaperReviewed 2026-10-03

How to use this reference

Document one actor/action/resource policy shared by all interfaces. Treat new helper interfaces as additions to the authorization model, and make missing enforcement fail closed. Compare remediation claims with the actual maintainer change: the reviewed artifact patch aligns alternate interface recognition with permission enforcement.

Before reading

  • Authentication versus object-level authorization
  • Applications with multiple interfaces to shared resources

Context and limits

  • The researcher limits exposure to self-hosted OSS basic-auth deployments with authenticated non-admin users; Databricks-managed MLflow is excluded.
  • Downstream code execution is a conditional modeled consequence in the article, not demonstrated production compromise or an automatic result of data access.
  • The article links a GraphQL commit that adds an authorization configuration switch; that commit alone does not establish the original GraphQL enforcement implementation or its complete patch chronology.
  • The maintainer artifact patch merged January 19, 2026, separately from February 3 publication. Exact affected-version and first-fixed-release bounds were not established from reviewed primary sources.
  • The underlying finding predates this article; 2026 labels the detailed educational publication. No bounty amount or independent exploit verification is claimed.

Sources and provenance

  1. CVE-2025-14297: MLflow Authorization Bypass Tachyon · reviewed 2026-10-03
  2. Enforce authorization on AJAX proxy artifact APIs MLflow · reviewed 2026-10-03
  3. Add an env var for controlling whether to enable GraphQL routes authorization MLflow · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software