[Medium] CVE-2026-3198 – MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authoriz...
Medium CVE-2026-3198 MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically, the `BEFORE_REQUEST_HANDLERS` dictionary in `mlflow/server/auth/__init__.py` does not include entries for...