CVE-2026-69111

HIGH

Milvus 2.6.22, 3.0.0 Unauthenticated Denial of Service via /management/stop

Title source: cna
STIX 2.1

Description

Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. Attackers can exploit the unprotected /management/stop endpoint, which bypasses REST API authentication middleware, by supplying a 'role' parameter to shut down the proxy, datanode, or querynode components, resulting in denial of service.

References (4)

Core 4
Core References
Exploit technical-description exploit
Researcher Disclosure
https://github.com/milvus-io/milvus/issues/50763
Issue Tracking issue-tracking
Pull Request (1)
https://github.com/milvus-io/milvus/pull/49847
Issue Tracking issue-tracking
Pull Request (2)
https://github.com/milvus-io/milvus/pull/51573

Scores

CVSS v3 7.5
EPSS 0.0057
EPSS Percentile 44.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (2)
milvus-io/milvus < 2.6.22
milvus-io/milvus 3.0.0
Published Aug 05, 2026
Tracked Since Aug 06, 2026