{"advisories":[{"id":"GHSA-7ppg-37fh-vcr6","source":"ghsa","title":"Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise","url":"https://github.com/advisories/GHSA-7ppg-37fh-vcr6"}],"cve":"CVE-2026-26190","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[0,2.5.27)"}},{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[2.6.0,2.6.10)"}}],"product":"milvus","vendor":"milvus"}],"created":"2026-02-13T21:42:56.474019+00:00","updated":"2026-08-03T08:30:17.835440+00:00","vendors":["milvus","milvus$PRODUCT$milvus"]},"epss":{"score":0.0405},"mitre":{"cpes":[],"created":"2026-02-13T18:44:33.465000+00:00","description":"Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable default authentication token derived from etcd.rootPath (default: by-dev), enabling arbitrary expression evaluation. The full REST API (/api/v1/*) is registered on the metrics/management port without any authentication, allowing unauthenticated access to all business operations including data manipulation and credential management. This vulnerability is fixed in 2.5.27 and 2.6.10.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/26xxx/CVE-2026-26190.json","references":["https://github.com/milvus-io/milvus/commit/92b74dd2e286006a83b4a5f07951027b32e718a9","https://github.com/milvus-io/milvus/releases/tag/v2.5.27","https://github.com/milvus-io/milvus/releases/tag/v2.6.10","https://github.com/milvus-io/milvus/security/advisories/GHSA-7ppg-37fh-vcr6"],"title":"Milvus Allows Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise","updated":"2026-02-26T14:44:20.414000+00:00","vendors":[],"weaknesses":["CWE-306"]},"nvd":{"cpes":["cpe:2.3:a:milvus:milvus:*:*:*:*:*:*:*:*"],"created":"2026-02-13T19:17:29.253000+00:00","description":"Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable default authentication token derived from etcd.rootPath (default: by-dev), enabling arbitrary expression evaluation. The full REST API (/api/v1/*) is registered on the metrics/management port without any authentication, allowing unauthenticated access to all business operations including data manipulation and credential management. This vulnerability is fixed in 2.5.27 and 2.6.10.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-26190.json","references":["https://github.com/milvus-io/milvus/commit/92b74dd2e286006a83b4a5f07951027b32e718a9","https://github.com/milvus-io/milvus/releases/tag/v2.5.27","https://github.com/milvus-io/milvus/releases/tag/v2.6.10","https://github.com/milvus-io/milvus/security/advisories/GHSA-7ppg-37fh-vcr6"],"title":null,"updated":"2026-06-17T10:25:54.857000+00:00","vendors":["milvus","milvus$PRODUCT$milvus"],"weaknesses":["CWE-306"]},"opencve":{"changes":[{"created":"2026-02-13T19:15:00+00:00","data":[{"details":{"new":"Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable default authentication token derived from etcd.rootPath (default: by-dev), enabling arbitrary expression evaluation. The full REST API (/api/v1/*) is registered on the metrics/management port without any authentication, allowing unauthenticated access to all business operations including data manipulation and credential management. This vulnerability is fixed in 2.5.27 and 2.6.10.","old":null},"type":"description"},{"details":{"new":"Milvus Allows Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise","old":null},"type":"title"},{"details":{"added":["CWE-306"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://github.com/milvus-io/milvus/commit/92b74dd2e286006a83b4a5f07951027b32e718a9","https://github.com/milvus-io/milvus/releases/tag/v2.5.27","https://github.com/milvus-io/milvus/releases/tag/v2.6.10","https://github.com/milvus-io/milvus/security/advisories/GHSA-7ppg-37fh-vcr6"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"1a91082d-4095-4381-9904-f59da2f4670a"},{"created":"2026-02-13T21:45:00+00:00","data":[{"details":["milvus","milvus$PRODUCT$milvus"],"type":"first_time"},{"details":{"added":["milvus","milvus$PRODUCT$milvus"],"removed":[]},"type":"vendors"}],"id":"da792aca-3f0c-4d62-a85e-a100b2d37ff3"},{"created":"2026-02-14T12:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"ec62cdec-020c-416a-b68b-c1f6d53386fe"},{"created":"2026-02-18T19:15:00+00:00","data":[{"details":{"added":["cpe:2.3:a:milvus:milvus:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"}],"id":"01219095-487a-4d24-9a50-afeec5380e43"}],"cpes":{"data":["cpe:2.3:a:milvus:milvus:*:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2026-02-13T18:44:33.465000+00:00","provider":"mitre"},"description":{"data":"Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable default authentication token derived from etcd.rootPath (default: by-dev), enabling arbitrary expression evaluation. The full REST API (/api/v1/*) is registered on the metrics/management port without any authentication, allowing unauthenticated access to all business operations including data manipulation and credential management. This vulnerability is fixed in 2.5.27 and 2.6.10.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.0405},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/milvus-io/milvus/commit/92b74dd2e286006a83b4a5f07951027b32e718a9","https://github.com/milvus-io/milvus/releases/tag/v2.5.27","https://github.com/milvus-io/milvus/releases/tag/v2.6.10","https://github.com/milvus-io/milvus/security/advisories/GHSA-7ppg-37fh-vcr6"],"providers":["mitre","nvd"]},"title":{"data":"Milvus Allows Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise","provider":"mitre"},"updated":{"data":"2026-04-17T20:00:09.005804+00:00","provider":"enrichment"},"vendors":{"data":["milvus","milvus$PRODUCT$milvus"],"providers":["nvd","enrichment"]},"weaknesses":{"data":["CWE-306"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-02-13T18:44:33.465000+00:00","description":"Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable default authentication token derived from etcd.rootPath (default: by-dev), enabling arbitrary expression evaluation. The full REST API (/api/v1/*) is registered on the metrics/management port without any authentication, allowing unauthenticated access to all business operations including data manipulation and credential management. This vulnerability is fixed in 2.5.27 and 2.6.10.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"Milvus Allows Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise","updated":"2026-02-13T19:37:23.724000+00:00","vendors":[],"vulnrichment_repo_path":"2026/26xxx/CVE-2026-26190.json","weaknesses":[]}}