S4E just found a high top 10 tcp port service scan
critical·Product Based Network Vulnerabilities·Updated Jun 8, 2026

CVE-2026-26190 Scanner

CVE-2026-26190 Scanner - Authentication Bypass vulnerability in Milvus

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-26190
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable default authentication token derived from etcd.rootPath (default: by-dev), enabling arbitrary expression evaluation. The full REST API (/api/v1/*) is registered on the metrics/management port without any authentication, allowing unauthenticated access to all business operations including data manipulation and credential management. This vulnerability is fixed in 2.5.27 and 2.6.10.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
milvusby milvus-io
< 2.5.27
Updated Aug 19, 2026View on NVD →
Detail

The Milvus platform is widely used in various industries for managing and searching large volumes of data. Organizations utilize Milvus to optimize their data retrieval processes, enhancing efficiency in applications such as artificial intelligence and analytics. Used by data scientists and software developers, Milvus offers robust features required for high-performance data manipulation tasks. Due to its scalability, Milvus is an ideal choice for enterprises handling voluminous datasets in the cloud. The platform is designed to integrate seamlessly with existing data systems, providing flexibility and speed. However, vulnerabilities like authentication bypasses can undermine its reliability if not adequately addressed.

Authentication bypass vulnerabilities can allow unauthorized users to gain access to restricted areas of a system. This vulnerability can be exploited by attackers to execute arbitrary operations or access sensitive data without proper authorization. In the case of Milvus, the use of weak default tokens and unsecured rest APIs increases the risk of such unauthorized access. Bypassing authentication means attackers can manipulate data or evaluate expressions without restrictions. The potential impact on the system's integrity and confidentiality is critical, necessitating immediate remediation. Unchecked, these vulnerabilities expose systems to widespread data breaches and system misuse.

The vulnerability in Milvus involves insecure default configurations on REST APIs operating on TCP port 9091. Attackers can exploit the weak default token mechanism to bypass the authentication process and gain unauthorized access. By manipulating API requests, attackers can induce arbitrary code execution or data manipulations. Testing endpoints like `/expr` with various payloads can reveal how bypass mechanisms work. The vulnerability mainly arises due to inadequate safeguards in the authentication process for the affected versions. This poses significant security threats as it allows full system control by unauthorized personnel.

When the Authentication Bypass vulnerability in Milvus is exploited, attackers potentially gain complete control over the affected system. Unauthorized access may lead to data theft, data corruption, or unauthorized modifications. Exploiting this flaw can allow attackers to run arbitrary expressions, risking the confidentiality and integrity of the system. Systematically, this can result in operational disruptions and loss of system reliability. Furthermore, once inside, attackers could install malicious programs or backdoors for long-term access. Such activities undermine the credibility of the organization using Milvus for their systems.

REFERENCES

Solution Advice
  • Immediately update Milvus to versions 2.5.27 or 2.6.10 or later to patch authentication vulnerabilities.
  • Ensure that all default authentication tokens are replaced with secure configurations.
  • Implement network-level firewalls to restrict unauthorized access to port 9091.
  • Regularly review and assess API configurations for any potential security weaknesses.
  • Deploy monitoring tools to detect suspicious activities involving unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.