Known CVE
Milvus - Unauthenticated Metrics API Access
Milvus < 2.5.27 and < 2.6.10 contains an authentication bypass caused by weak default token and unauthenticated REST API on TCP port 9091, letting attackers perform arbitrary expression evaluation and data manipulation, exploit requires network access to port 9091.
CVE-2026-26190
Critical2026CVSS 9.8CWE-306
cve2026 · milvus · auth-bypass · unauth · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website