SSRF Vulnerability in Zilliz Attu Applications
CVE-2026-105048

4MEDIUM

Key Information:

Vendor

Zilliz

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-105048?

The Playground feature in Zilliz Attu prior to version 3.0.0 is susceptible to a Server-Side Request Forgery (SSRF) attack. This vulnerability allows an attacker to send crafted requests that can proxy connections to internal network resources, thereby gaining unauthorized access to private IP addresses. Such exposure can lead to further exploits and data breaches, emphasizing the need for users to upgrade to the latest version to mitigate the associated risks.

Affected Version(s)

Attu 2.6.5 < 3.0.0

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.