ADVISORY UNAUTH-2026-0008
TYPE exposure-class
PRODUCT Qdrant
SEVERITY CRITICAL
Qdrant vector database open without authentication
published 2026-08-05 · updated 2026-08-05
Why it matters
Your vector database answers anyone on the internet. Every embedding you stored can be read, poisoned, modified or deleted. RAG and agent-memory stores often hold document text and long-term agent state (OWASP ASI06). Qdrant ships with no authentication by default, so this is a configuration choice, not a bug.
What a probe sees
GET :6333/collections lists your vector collections with no API key.
Internet-facing exposure — observable from the public internet with GET-only probes (the same probes unauth.dev sends).
agent-memory-store OWASP ASI06
In the wild
HONEYPOT EVIDENCE · only unauth.dev publishes this
SERVICE qdrant
PROBES (30d) 22
FIRST SEEN 2026-08-03
LAST SEEN 2026-08-05
Day-granularity probe counts from the unauth.dev botwatch honeypot (22 observed across retained history), refreshed monthly. No source IPs exist in the underlying data. Live view: /botwatch.
Fix it
References
- https://qdrant.tech/documentation/guides/security/
- https://qdrant.tech/documentation/guides/configuration/
- https://genai.owasp.org/2025/12/09/owasp-top-10-for-agentic-applications-the-benchmark-for-agentic-security-in-the-age-of-autonomous-ai/
Cite this record
unauth.dev advisory UNAUTH-2026-0008 — observed 2026-08 · CC-BY 4.0
Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0008. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.