CVE-2026-69111
HIGHMilvus 2.6.22, 3.0.0 Unauthenticated Denial of Service via /management/stop
Title source: cnaDescription
Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. Attackers can exploit the unprotected /management/stop endpoint, which bypasses REST API authentication middleware, by supplying a 'role' parameter to shut down the proxy, datanode, or querynode components, resulting in denial of service.
References (4)
Core 4
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/milvus-io/milvus/issues/50763
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/milvus-unauthenticated-denial-of-service-via-management-stop
Scores
CVSS v3
7.5
EPSS
0.0057
EPSS Percentile
44.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-306
Status
published
Products (2)
milvus-io/milvus
< 2.6.22
milvus-io/milvus
3.0.0
Published
Aug 05, 2026
Tracked Since
Aug 06, 2026