
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26190 is a critical authentication bypass vulnerability in Milvus, an open-source vector database built for generative AI applications. The vulnerability affects all Milvus versions prior to 2.5.27 and versions 2.6.0 through 2.6.9 (prior to 2.6.10), and was disclosed on February 11–13, 2026 via a GitHub Security Advisory and NVD publication. It carries a CVSS v3.1 base score of 9.8 (Critical), reflecting network-accessible exploitation requiring no authentication or user interaction (GitHub Advisory, Red Hat CVE).
The root cause is classified as CWE-306 (Missing Authentication for Critical Function). Milvus exposes TCP port 9091 by default with two distinct weaknesses: (1) the /expr debug endpoint accepts an auth parameter that defaults to the etcd.rootPath value (by-dev), a well-known and predictable token that enables arbitrary internal Go expression evaluation; and (2) the full REST API (/api/v1/*) is registered on the metrics/management HTTP server via registerHTTPServer() in internal/distributed/proxy/service.go without any authentication middleware, even when authentication is enabled on the primary gRPC/HTTP ports. The fix adds an authenticate middleware to the metrics port's API group when AuthorizationEnabled is true (GitHub Advisory, Patch Commit). Public proof-of-concept code is included in the security advisory.
An unauthenticated remote attacker with network access to port 9091 can fully compromise a Milvus instance. Exploitation enables exfiltration of sensitive secrets (MinIO access keys, etcd credentials, user password hashes), arbitrary data manipulation (creating, modifying, and deleting collections and records), unauthorized credential management (creating admin users, resetting passwords), denial of service (stopping the proxy service or dropping databases), and potential remote code execution via access log configuration manipulation to write arbitrary files to the filesystem (GitHub Advisory).
Public proof-of-concept code is included directly in the GitHub Security Advisory, demonstrating both the /expr endpoint exploitation and unauthenticated REST API access with working Python scripts. The advisory notes that a significant number of Milvus instances are discoverable via internet-wide scanning using the pattern http.body="404 page not found" && port="9091", indicating real-world exposure. The EPSS score is 0.00323 (low probability of near-term exploitation), and there is no current evidence of active in-the-wild exploitation or CISA KEV listing (GitHub Advisory). A Nuclei template was added to the projectdiscovery/nuclei-templates repository, further lowering the bar for exploitation. The vulnerability was discovered and reported by YingLin Xie, with independent reports from researchers 0x1f and zznQ.
http.body="404 page not found" && port="9091" to find hosts with port 9091 open.http://<target>:9091/expr with the default auth token by-dev and a malicious Go expression, e.g., ?auth=by-dev&code=param.MinioCfg.SecretAccessKey.GetValue() to leak MinIO credentials, or ?auth=by-dev&code=rootcoord.meta.GetCredential(ctx,'root') to retrieve root password hashes.http://<target>:9091/api/v1/credential to create a new administrative user (e.g., POST with {"username": "attacker_user", "password": "<base64>"}) or enumerate existing users via GET /api/v1/credential/users./expr endpoint, manipulate access log configuration parameters (proxy.accessLog.localPath, proxy.accessLog.filename, proxy.accessLog.formatters.base.format) to write arbitrary content to attacker-controlled file paths on the server (GitHub Advisory)./expr, /api/v1/credential, /api/v1/collections, or other REST API paths on port 9091 from non-internal sources./expr?auth=by-dev&code=... with encoded Go expressions; REST API calls to /api/v1/* on port 9091 without authentication headers; creation of new user accounts not initiated by administrators.proxy.accessLog.localPath (e.g., /tmp/evil.sh or similar); modifications to access log configuration files.etcd.rootPath or access log configuration parameters (proxy.accessLog.*) not initiated by administrators; unexpected new user credentials appearing in the Milvus credential store (GitHub Advisory).Upgrade Milvus to version 2.5.27 (for the 2.5.x branch) or 2.6.10 (for the 2.6.x branch), both designated as critical security releases that add authentication middleware to the metrics port API (Milvus 2.5.27 Release, Milvus 2.6.10 Release). As interim mitigations until patching is possible: block external access to TCP port 9091 using firewall rules or Kubernetes network policies; bind port 9091 to localhost (127.0.0.1:9091) so it is not externally accessible; and change etcd.rootPath from the default by-dev to a strong random value (partial mitigation only — does not address the unauthenticated REST API). Do not expose port 9091 outside the internal network in Docker or Kubernetes deployments (GitHub Advisory).
The vulnerability received coverage from The Hacker Wire and was discussed on Bluesky and Mastodon shortly after disclosure. Security researchers at offseq.com flagged it on their threat radar, and it was featured in a PoC weekly digest by tonyharris.io. Check Point Research published two advisories (cpai-2026-0869 and cpai-2026-0891) referencing the vulnerability. The Linux Security community noted it via SUSE's govulncheck advisory. Community reaction highlighted the severity of exposing a full unauthenticated REST API on a metrics port as a significant design oversight, particularly given Milvus's growing adoption in AI/ML production environments.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."