Vulnerability Description
Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. Attackers can exploit the unprotected /management/stop endpoint, which bypasses REST API authentication middleware, by supplying a 'role' parameter to shut down the proxy, datanode, or querynode components, resulting in denial of service.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/milvus-io/milvus/issues/50763
- https://github.com/milvus-io/milvus/pull/49847
- https://github.com/milvus-io/milvus/pull/51573
- https://www.vulncheck.com/advisories/milvus-unauthenticated-denial-of-service-vi
FAQ
What is CVE-2026-69111?
CVE-2026-69111 is a vulnerability with a CVSS score of 7.5 (HIGH). Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the ma...
How severe is CVE-2026-69111?
CVE-2026-69111 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-69111?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.