peter bassill · operator
$ cve CVE-2026-26190 JSON

CVE-2026-26190

9.8
CRITICAL · CVSS 3.1 · EPSS 4.1% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable default authentication token derived from etcd.rootPath (default: by-dev), enabling arbitrary expression evaluation. The full REST API (/api/v1/*) is registered on the metrics/management port without any authentication, allowing unauthenticated access to all business operations including data manipulation and credential management. This vulnerability is fixed in 2.5.27 and 2.6.10.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.14% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploitnone known
Published2026-02-13
Last modified2026-06-17

Affected (1)

VendorProduct
milvusmilvus

References

→ the Explorer  ·  watch your stack  ·  NVD