CVE-2026-26190Disclosure(milvus / milvus)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch milvus milvus systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable default authentication token derived from etcd.rootPath (default: by-dev), enabling arbitrary expression evaluation. The full REST API (/api/v1/*) is registered on the metrics/management port without any authentication, allowing unauthenticated access to all business operations including data manipulation and credential management. This vulnerability is fixed in 2.5.27 and 2.6.10.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • milvus

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-02-13); latest day: 1
  • 9 total mentions across 4 days

Affected systems

Vendors
Products
milvus

Deep dive

Activity timeline9 mentions / 4d
01234Mentions · 2026-02-13: 4Mentions · 2026-02-14: 2Mentions · 2026-02-15: 2Mentions · 2026-02-18: 1PoC Mentioned / Linked · 2026-02-14: 1Patch / Workaround · 2026-02-13: 2Patch / Workaround · 2026-02-14: 2Technical Details · 2026-02-13: 4Technical Details · 2026-02-14: 2Technical Details · 2026-02-15: 2Technical Details · 2026-02-18: 102-1302-1402-1502-18
Signal classification3 categories
Disclosure
444.4%
Patch
444.4%
General
111.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-02-134
Disclosure1General1Patch2
2026-02-142
Patch2
2026-02-152
Disclosure2
2026-02-181
Disclosure1
Full discourse9 posts
  • Sami Laiho@samilaiho
    Patch

    Milvus Allows Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise URL: https://nvd.nist.gov/vuln/detail/CVE-2026-26190 Classification: Critical, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv3.1: 9.8

    Post summary

    Milvus is vulnerable to unauthenticated access on port 9091, which could lead to critical system compromise. An official patch has been released and a proof‑of‑concept PoC exists, though no active exploitation is reported.

    01011589
    30.4K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-26190 Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables auth… https://www.cve.org/CVERecord?id=CVE-2026-26190

    Post summary

    Milvus CVE‑2026‑26190 exposes TCP port 9091 by default in older releases, allowing unauthorized access; the issue is resolved in versions 2.5.27 and 2.6.10.

    00020190
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-26190 Unauthenticated Remote Access and Arbitrary Expression Evaluation... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26190 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A brief notice of CVE-2026-26190 highlighting unauthenticated remote access and arbitrary expression evaluation, accompanied by a link to more details.

    0001039
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26190 (CVSS:9.8, CRITICAL) is Awaiting Analysis. Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus expose..https://nvd.nist.gov/vuln/detail/CVE-2026-26190 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    Milvus vector database has a critical vulnerability (CVE‑2026‑26190) affecting versions before 2.5.27 and 2.6.10, with a CVSS score of 9.8 and currently awaiting analysis.

    0000045
    171 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-26190: Milvus Allows Unauthenticated Ac... Milvus's metrics port 9091 exposes full REST API with zero auth, plus weak token-based RCE via /expr - trivial to weapo... https://zerodaysignal.com/vulnerability/CVE-2026-26190 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-26190 for Milvus, noting unauthenticated REST API access on port 9091 and a weak token‑based RCE via /expr.

    0000067
    131 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Unauthenticated API access on metrics port affects `Milvus` (CVE-2026-26190), enabling potential system compromise. Review network exposure for `Milvus` deployments. #infosec #APIsecurity #Milvus https://www.pulsepatch.io/posts/cve-2026-26190-milvus-unauthenticated-metrics-api-access

    Post summary

    The post announces a CVE‑2026‑26190 vulnerability in Milvus that allows unauthenticated API access on the metrics port, potentially enabling system compromise, but it does not provide a PoC, exploit, or patch information.

    0000039
    1 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 Critical alert: Milvus (vector DB for AI) has a CRITICAL auth bypass (CVE-2026-26190, CVSS 9.8). Unauthenticated access on port 9091 exposes data & credentials! Upgrade to 2.5.27/2.6.10 now. 🛡️ https://radar.offseq.com/threat/cve-2026-26190-cwe-306-missing-authentication-for... https://t.co/TqitbSfxKb

    Post summary

    Milvus vector DB suffers a critical auth bypass (CVE-2026-26190, CVSS 9.8) exposing data on port 9091; users are advised to upgrade to 2.5.27 or 2.6.10.

    0000045
    268 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-26190: CRITICAL] Warning: Prior versions of Milvus expose TCP port 9091 by default, leading to authentication bypasses. Upgrade to versions 2.5.27 or 2.6.10 to fix this vulnerability. #CyberSecurity#cve,CVE-2026-26190,#cybersecurity https://cvefind.com/CVE-2026-26190

    Post summary

    Milvus versions before 2.5.27/2.6.10 expose TCP port 9091, enabling authentication bypasses; upgrading resolves the critical CVE-2026-26190.

    0000048
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-26190 - Critical Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. ... https://www.thehackerwire.com/vulnerability/CVE-2026-26190/ https://t.co/d9e8XOtqlk

    Post summary

    Milvus vector database versions prior to 2.5.27/2.6.10 expose TCP port 9091 by default, enabling authentication bypasses, making CVE-2026-26190 a critical disclosure.

    0000056
    112 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmilvusmilvus---

Explore more