Authentication Bypass Vulnerability in Milvus Open-Source Vector Database
CVE-2026-26190

9.8CRITICAL

Key Information:

Vendor

Milvus-io

Status
Vendor
CVE Published:
13 February 2026

What is CVE-2026-26190?

Milvus, a popular open-source vector database tailored for generative AI applications, has revealed a significant authentication bypass vulnerability that impacts its versions prior to 2.5.27 and 2.6.10. The default exposure of TCP port 9091 enables unauthorized access through a weak authentication token derived from etcd.rootPath, while sensitive endpoints remain unprotected. This flaw allows attackers to freely interact with critical business operations, including data manipulation and credential management, posing serious risks to data integrity and system security. Upgrading to the fixed versions 2.5.27 and 2.6.10 is strongly recommended to mitigate these vulnerabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

milvus < 2.5.27 < 2.5.27

milvus >= 2.6.0, < 2.6.10 < 2.6.0, 2.6.10

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.