ADVISORY UNAUTH-2026-0010
TYPE exposure-class
PRODUCT Milvus
SEVERITY HIGH
Milvus vector database exposed to the internet
published 2026-08-05 · updated 2026-08-05
Why it matters
Your Milvus deployment answers anyone on the internet — its health endpoint fingerprints the exact version, and the gRPC data API (:19530) on the same host has no authentication unless you enabled it. Every embedding you stored can be read, poisoned, modified or deleted. RAG and agent-memory stores often hold document text and long-term agent state (OWASP ASI06). An exposed Attu admin UI confirms the deployment and gives an attacker a console to attach to it.
What a probe sees
GET :9091/healthz answers with a Milvus Server header (version included) without auth.
Internet-facing exposure — observable from the public internet with GET-only probes (the same probes unauth.dev sends).
agent-memory-store OWASP ASI06
In the wild
No honeypot telemetry for this service yet (in_the_wild: null in the dataset). We do not invent numbers. The block appears when the honeypot has real data.
Fix it
References
- https://milvus.io/docs/authenticate.md
- https://milvus.io/docs/configure_security.md
- https://genai.owasp.org/2025/12/09/owasp-top-10-for-agentic-applications-the-benchmark-for-agentic-security-in-the-age-of-autonomous-ai/
Cite this record
unauth.dev advisory UNAUTH-2026-0010 — published 2026-08 · CC-BY 4.0
Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0010. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.