Milvus - Authentication Bypass (CVE-2026-26190)
Description
Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable default authentication token derived from etcd.rootPath (default: by-dev), enabling arbitrary expression evaluation. The full REST API (/api/v1/*) is registered on the metrics/management port without any authentication, allowing unauthenticated access to all business operations including data manipulation and credential management. This vulnerability is fixed in 2.5.27 and 2.6.10.
psychologyCrowdSec Analysis
CVE-2026-26190 is a critical authentication bypass vulnerability in Milvus, an open-source vector database, affecting versions prior to 2.5.27 and 2.6.10. Due to exposed TCP port 9091 and weak default authentication, unauthenticated attackers can access sensitive REST API endpoints, enabling arbitrary data manipulation, credential management, and potentially full system compromise. This flaw poses a significant risk for remote exploitation and unauthorized control over Milvus deployments.
CrowdSec has been tracking this vulnerability and its exploits since 1st of July 2026.
CrowdSec has not observed any significant exploitation activity targeting CVE-2026-26190 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.
Attackers exploit unauthenticated access to the Milvus Metrics API on port 9091 by sending requests to the /expr endpoint with the auth=by-dev parameter, allowing arbitrary expression evaluation and data manipulation without authentication.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2026-02-13 |
| Rule Released | 2026-07-01 |
| CrowdSec First Seen | 2026-08-01 |
Remediation & Protection
External References
- https://github.com/milvus-io/milvus/security/advisories/GHSA-7ppg-37fh-vcr6
- https://github.com/milvus-io/milvus/releases/tag/v2.6.10
- https://github.com/milvus-io/milvus/releases/tag/v2.5.27
- https://github.com/milvus-io/milvus/commit/92b74dd2e286006a83b4a5f07951027b32e718a9
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-26190.yaml