Skip to content

Known CVE

Milvus - Unauthenticated Metrics API Access

Milvus < 2.5.27 and < 2.6.10 contains an authentication bypass caused by weak default token and unauthenticated REST API on TCP port 9091, letting attackers perform arbitrary expression evaluation and data manipulation, exploit requires network access to port 9091.

CVE-2026-26190

Critical2026CVSS 9.8CWE-306

cve2026 · milvus · auth-bypass · unauth · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website