Impact
Milvus releases before 2.5.27 and 2.6.0 through 2.6.9 can expose management REST behavior on the metrics/management port 9091 without the authentication operators expect on the primary API. If that listener is reachable from untrusted networks, attackers may be able to manage users, collections, and data, and the related advisory also describes dangerous debug functionality on the same management surface.
Covered by FixVibe
FixVibe's verified active scans flag Milvus deployments whose management REST API on the metrics port answers credential-management requests without authentication, and show the affected endpoint and status. Treat a finding as confirmed exposure of the management REST API and remediate urgently.
Remediation
Upgrade Milvus to 2.5.27, 2.6.10, or a later fixed release. Restrict port 9091 to trusted monitoring networks, VPN, or private service-network paths, and avoid exposing it through public load balancers, Kubernetes Services/Ingress, Docker port mappings, or cloud security groups. If the port was reachable from the internet, review Milvus users, credentials, collections, audit/access logs, object-store credentials, and etcd credentials. Rerun a verified active scan after the listener is patched or unreachable to unauthenticated clients.
