Unrated severityNVD Advisory· Published Aug 5, 2026
Milvus 2.6.22, 3.0.0 Unauthenticated Denial of Service via /management/stop
CVE-2026-69111
Description
Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. Attackers can exploit the unprotected /management/stop endpoint, which bypasses REST API authentication middleware, by supplying a 'role' parameter to shut down the proxy, datanode, or querynode components, resulting in denial of service.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/milvus-io/milvus/issues/50763mitretechnical-descriptionexploit
- www.vulncheck.com/advisories/milvus-unauthenticated-denial-of-service-via-management-stopmitrethird-party-advisory
- github.com/milvus-io/milvus/pull/49847mitreissue-tracking
- github.com/milvus-io/milvus/pull/51573mitreissue-tracking
News mentions
0No linked articles in our index yet.