


Perceptive Security
SOC/SIEM Consultancy

Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by send…
Published:
4 August 2026 at 22:00:00
Alert date:
5 August 2026 at 21:03:13
Source:
nvd.nist.gov
Database & Storage, Web Technologies
Milvus versions through 2.6.22 and 3.0.0 contain an unauthenticated denial of service vulnerability affecting the management server on port 9091. The unprotected /management/stop endpoint bypasses REST API authentication middleware, allowing remote attackers to send a crafted HTTP GET request with a 'role' parameter to shut down critical service components. Affected components include proxy, datanode, and querynode, whose termination results in denial of service. The vulnerability requires no authentication, making it trivially exploitable by remote attackers. Multiple GitHub issues and pull requests have been filed addressing the flaw, and a VulnCheck advisory has been published. The issue highlights a significant authentication gap in Milvus's management interface design.
Technical details
Mitigation steps:
Affected products:
Milvus 2.6.22
Milvus 3.0.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-69111
https://github.com/milvus-io/milvus/issues/50763
https://github.com/milvus-io/milvus/pull/49847
https://github.com/milvus-io/milvus/pull/51573
https://www.vulncheck.com/advisories/milvus-unauthenticated-denial-of-service-via-management-stop
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
