How to use this reference
Document one actor/action/resource policy shared by all interfaces. Treat new helper interfaces as additions to the authorization model, and make missing enforcement fail closed. Compare remediation claims with the actual maintainer change: the reviewed artifact patch aligns alternate interface recognition with permission enforcement.
Before reading
- Authentication versus object-level authorization
- Applications with multiple interfaces to shared resources
Context and limits
- The researcher limits exposure to self-hosted OSS basic-auth deployments with authenticated non-admin users; Databricks-managed MLflow is excluded.
- Downstream code execution is a conditional modeled consequence in the article, not demonstrated production compromise or an automatic result of data access.
- The article links a GraphQL commit that adds an authorization configuration switch; that commit alone does not establish the original GraphQL enforcement implementation or its complete patch chronology.
- The maintainer artifact patch merged January 19, 2026, separately from February 3 publication. Exact affected-version and first-fixed-release bounds were not established from reviewed primary sources.
- The underlying finding predates this article; 2026 labels the detailed educational publication. No bounty amount or independent exploit verification is claimed.
Sources and provenance
- CVE-2025-14297: MLflow Authorization Bypass Tachyon · reviewed 2026-10-03
- Enforce authorization on AJAX proxy artifact APIs MLflow · reviewed 2026-10-03
- Add an env var for controlling whether to enable GraphQL routes authorization MLflow · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.