CVE-2026-26190: CWE-306: Missing Authentication for Critical Function in milvus-io milvus
Milvus versions prior to 2.5.27 and 2.6.10 have a critical authentication bypass vulnerability. The default TCP port 9091 exposes a debug endpoint (/expr) that uses a weak, predictable authentication token, allowing arbitrary expression evaluation. Additionally, the full REST API is accessible on the metrics/management port without authentication, enabling unauthenticated access to all business operations including data and credential management. This vulnerability is fixed in versions 2.5.27 and 2.6.10.
AI Analysis
Technical Summary
CVE-2026-26190 in Milvus (an open-source vector database) is a missing authentication vulnerability (CWE-306) affecting versions prior to 2.5.27 and 2.6.10. The default exposure of TCP port 9091 allows bypassing authentication because the /expr debug endpoint uses a weak, predictable token derived from the default etcd.rootPath value. Furthermore, the full REST API is registered on the metrics/management port without any authentication, permitting unauthenticated access to critical business functions such as data manipulation and credential management. This vulnerability has a CVSS 3.1 score of 9.8 (critical) and is resolved in versions 2.5.27 and 2.6.10.
Potential Impact
An attacker can bypass authentication controls to perform arbitrary expression evaluation and gain unauthenticated access to all business operations, including data manipulation and credential management. This results in full compromise of confidentiality, integrity, and availability of the Milvus service.
Mitigation Recommendations
Upgrade Milvus to version 2.5.27 or later, or 2.6.10 or later, where this vulnerability is fixed. No other mitigations are indicated by the vendor advisory. Patch status is confirmed fixed in these versions.
CVE-2026-26190: CWE-306: Missing Authentication for Critical Function in milvus-io milvus
Description
Milvus versions prior to 2.5.27 and 2.6.10 have a critical authentication bypass vulnerability. The default TCP port 9091 exposes a debug endpoint (/expr) that uses a weak, predictable authentication token, allowing arbitrary expression evaluation. Additionally, the full REST API is accessible on the metrics/management port without authentication, enabling unauthenticated access to all business operations including data and credential management. This vulnerability is fixed in versions 2.5.27 and 2.6.10.
CVSS v3.1
Score 9.8critical
Affected software
milvus-io
milvus
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-26190 in Milvus (an open-source vector database) is a missing authentication vulnerability (CWE-306) affecting versions prior to 2.5.27 and 2.6.10. The default exposure of TCP port 9091 allows bypassing authentication because the /expr debug endpoint uses a weak, predictable token derived from the default etcd.rootPath value. Furthermore, the full REST API is registered on the metrics/management port without any authentication, permitting unauthenticated access to critical business functions such as data manipulation and credential management. This vulnerability has a CVSS 3.1 score of 9.8 (critical) and is resolved in versions 2.5.27 and 2.6.10.
Potential Impact
An attacker can bypass authentication controls to perform arbitrary expression evaluation and gain unauthenticated access to all business operations, including data manipulation and credential management. This results in full compromise of confidentiality, integrity, and availability of the Milvus service.
Mitigation Recommendations
Upgrade Milvus to version 2.5.27 or later, or 2.6.10 or later, where this vulnerability is fixed. No other mitigations are indicated by the vendor advisory. Patch status is confirmed fixed in these versions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-02-11T19:56:24.812Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 698f793ac9e1ff5ad85a8a5c
Added to database: 02/13/2026, 19:19:22 UTC
Last enriched: 07/06/2026, 23:32:33 UTC
Last updated: 09/10/2026, 22:09:23 UTC
Views: 1988
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.