Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-7ppg-37fh-vcr6 | Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise |
Wed, 18 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:milvus:milvus:*:*:*:*:*:*:*:* |
Sat, 14 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 13 Feb 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Milvus
Milvus milvus |
|
| Vendors & Products |
Milvus
Milvus milvus |
Fri, 13 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable default authentication token derived from etcd.rootPath (default: by-dev), enabling arbitrary expression evaluation. The full REST API (/api/v1/*) is registered on the metrics/management port without any authentication, allowing unauthenticated access to all business operations including data manipulation and credential management. This vulnerability is fixed in 2.5.27 and 2.6.10. | |
| Title | Milvus Allows Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-26T14:44:20.414Z
Reserved: 2026-02-11T19:56:24.812Z
Link: CVE-2026-26190
Updated: 2026-02-13T19:37:23.724Z
Status : Analyzed
Published: 2026-02-13T19:17:29.253
Modified: 2026-02-18T19:11:12.333
Link: CVE-2026-26190
No data.
OpenCVE Enrichment
Updated: 2026-04-17T20:00:09Z
Github GHSA