{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-26190/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Milvus (2.5.x)","Milvus (2.6.x)","Milvus (\u003c= 2.6.22, 3.0.0)"],"_cs_severities":["critical"],"_cs_tags":["milvus","authentication-bypass","remote-code-execution","cve-2025-64513","cve-2026-26190"],"_cs_type":"advisory","_cs_vendors":["Milvus"],"content_html":"\u003cp\u003eMilvus is susceptible to critical authentication vulnerabilities that permit unauthenticated remote attackers to bypass security controls and gain administrative access. The most notable issue, CVE-2025-64513, involves a hardcoded 'sourceId' header ('@@milvus-member@@') used in the \u003ccode\u003evalidSourceID()\u003c/code\u003e function within \u003ccode\u003einternal/proxy/authentication_interceptor.go\u003c/code\u003e. This header forces the proxy to skip authentication entirely, allowing an attacker to forge an identity and gain administrative privileges by providing a base64-encoded 'root' credential.\u003c/p\u003e\n\u003cp\u003eFurthermore, CVE-2026-26190 affects two other components: the \u003ccode\u003e/expr\u003c/code\u003e debug endpoint on management port 9091, which utilizes a weak, predictable default authentication token ('by-dev'), and the lack of authentication on the internal gRPC port 53100. These flaws allow arbitrary expression execution and unauthorized database access. While newer versions (2.6.10+) mitigate these by disabling the \u003ccode\u003e/expr\u003c/code\u003e endpoint by default and closing internal port 53100, existing unpatched instances remain at high risk.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify exposed Milvus management (9091) or proxy (19530) ports.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a gRPC request or HTTP request targeting the proxy port (19530).\u003c/li\u003e\n\u003cli\u003eAttacker injects the 'sourceId' header with the value '@@milvus-member@@' to trigger the authentication interceptor bypass (CVE-2025-64513).\u003c/li\u003e\n\u003cli\u003eAttacker provides authorization credentials formatted as base64 'root:fake_password' to masquerade as an administrator.\u003c/li\u003e\n\u003cli\u003eAttacker gains full administrative access to the Milvus proxy.\u003c/li\u003e\n\u003cli\u003eAlternatively, the attacker targets port 9091 and authenticates to the /expr endpoint using the default token 'by-dev' (CVE-2026-26190).\u003c/li\u003e\n\u003cli\u003eAttacker submits malicious 'expr-lang' expressions through the /expr endpoint to achieve arbitrary code execution.\u003c/li\u003e\n\u003cli\u003eAttacker executes database queries or administrative commands to exfiltrate or manipulate stored vector data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants an attacker full administrative control over the Milvus database instance. This impact includes the potential for total data exfiltration, database manipulation, and further compromise of the underlying infrastructure hosting the Milvus service. As a vector database, Milvus often stores critical AI/ML embeddings and intellectual property, making it a high-value target for threat actors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Milvus deployments to version 2.6.10 or later immediately to patch CVE-2025-64513 and CVE-2026-26190.\u003c/li\u003e\n\u003cli\u003eImplement network-level access control lists (ACLs) to restrict access to ports 19530, 9091, and 53100 to known trusted internal IP addresses only.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual authentication headers or high-frequency requests to the /expr debug endpoint.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately possible, explicitly disable the /expr endpoint by setting \u003ccode\u003ecommon.security.exprEnabled\u003c/code\u003e to \u003ccode\u003efalse\u003c/code\u003e in the Milvus configuration.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T21:20:43Z","date_published":"2026-08-05T06:08:49Z","id":"https://feed.craftedsignal.io/briefs/2026-08-milvus-auth-bypass/","summary":"Milvus vector database versions prior to 2.5.27 and 2.6.10 are vulnerable to multiple authentication bypass flaws and arbitrary expression execution, allowing attackers to gain full administrative access.","title":"Authentication Bypass and RCE Vulnerabilities in Milvus","url":"https://feed.craftedsignal.io/briefs/2026-08-milvus-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-26190","version":"https://jsonfeed.org/version/1.1"}