CVE-2026-26190 Scanner

CVE-2026-26190 Scanner - Authentication Bypass vulnerability in Milvus

Short Info


Level

Critical

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

25 days 15 hours

Scan only one

Domain, Subdomain, IPv4

Toolbox

The Milvus platform is widely used in various industries for managing and searching large volumes of data. Organizations utilize Milvus to optimize their data retrieval processes, enhancing efficiency in applications such as artificial intelligence and analytics. Used by data scientists and software developers, Milvus offers robust features required for high-performance data manipulation tasks. Due to its scalability, Milvus is an ideal choice for enterprises handling voluminous datasets in the cloud. The platform is designed to integrate seamlessly with existing data systems, providing flexibility and speed. However, vulnerabilities like authentication bypasses can undermine its reliability if not adequately addressed.

Authentication bypass vulnerabilities can allow unauthorized users to gain access to restricted areas of a system. This vulnerability can be exploited by attackers to execute arbitrary operations or access sensitive data without proper authorization. In the case of Milvus, the use of weak default tokens and unsecured rest APIs increases the risk of such unauthorized access. Bypassing authentication means attackers can manipulate data or evaluate expressions without restrictions. The potential impact on the system's integrity and confidentiality is critical, necessitating immediate remediation. Unchecked, these vulnerabilities expose systems to widespread data breaches and system misuse.

The vulnerability in Milvus involves insecure default configurations on REST APIs operating on TCP port 9091. Attackers can exploit the weak default token mechanism to bypass the authentication process and gain unauthorized access. By manipulating API requests, attackers can induce arbitrary code execution or data manipulations. Testing endpoints like `/expr` with various payloads can reveal how bypass mechanisms work. The vulnerability mainly arises due to inadequate safeguards in the authentication process for the affected versions. This poses significant security threats as it allows full system control by unauthorized personnel.

When the Authentication Bypass vulnerability in Milvus is exploited, attackers potentially gain complete control over the affected system. Unauthorized access may lead to data theft, data corruption, or unauthorized modifications. Exploiting this flaw can allow attackers to run arbitrary expressions, risking the confidentiality and integrity of the system. Systematically, this can result in operational disruptions and loss of system reliability. Furthermore, once inside, attackers could install malicious programs or backdoors for long-term access. Such activities undermine the credibility of the organization using Milvus for their systems.

REFERENCES

Get started to protecting your digital assets