AI Data at Risk: Critical Milvus Flaw (CVSS 9.8) Exposes Database via Port 9091
ID: 632f7234-3d68-53de-813d-be7035f5e444
STIX ID: report--632f7234-3d68-53de-813d-be7035f5e444
Feed Name: securityonline.info
A critical vulnerability (CVSS 9.8) was found in Milvus versions < 2.5.27 and >= 2.6.0, < 2.6.10 that exposed TCP port 9091 by default, allowing unauthenticated access to a debug expression endpoint and the full REST API; attackers who reach the port can steal secrets, delete or corrupt data, create admin accounts, and potentially achieve remote code execution. Maintainers released patches (upgrade to 2.5.27 or 2.6.10) and advise blocking external access to port 9091 if immediate patching is not possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
