FixVibe

critical

Milvus Unauthenticated REST API Access on Metrics Port (CVE-2026-26190)

FixVibe verified active scans flag Milvus metrics-port REST API exposure for CVE-2026-26190 / GHSA-7ppg-37fh-vcr6.

CVE-2026-26190GHSA-7ppg-37fh-vcr6CWE-306CWE-749CWE-1188

Impact

Milvus releases before 2.5.27 and 2.6.0 through 2.6.9 can expose management REST behavior on the metrics/management port 9091 without the authentication operators expect on the primary API. If that listener is reachable from untrusted networks, attackers may be able to manage users, collections, and data, and the related advisory also describes dangerous debug functionality on the same management surface.

Covered by FixVibe

FixVibe's verified active scans flag Milvus deployments whose management REST API on the metrics port answers credential-management requests without authentication, and show the affected endpoint and status. Treat a finding as confirmed exposure of the management REST API and remediate urgently.

Remediation

Upgrade Milvus to 2.5.27, 2.6.10, or a later fixed release. Restrict port 9091 to trusted monitoring networks, VPN, or private service-network paths, and avoid exposing it through public load balancers, Kubernetes Services/Ingress, Docker port mappings, or cloud security groups. If the port was reachable from the internet, review Milvus users, credentials, collections, audit/access logs, object-store credentials, and etcd credentials. Rerun a verified active scan after the listener is patched or unreachable to unauthenticated clients.