← advisory ledger

ADVISORY UNAUTH-2026-0021
TYPE exposure-class
PRODUCT Redis
SEVERITY CRITICAL

CRITICAL

Redis management console exposed to the internet

published 2026-08-05 · updated 2026-08-05

Why it matters

A RedisInsight or Redis Commander console is reachable without login. From there anyone can browse (and often change) keys in the Redis instances it manages — sessions, caches, and agent memory / tool state that RAG and agent stacks commonly park in Redis (OWASP ASI06). We detect the HTTP console, not the raw Redis wire protocol.

What a probe sees

GET :5540/api/health answers with a RedisInsight marker (or the Redis Commander page on :8081) without login.

Internet-facing exposure — observable from the public internet with GET-only probes (the same probes unauth.dev sends).

agent-memory-store OWASP ASI06

In the wild

No honeypot telemetry for this service yet (in_the_wild: null in the dataset). We do not invent numbers. The block appears when the honeypot has real data.

Fix it

Fix card: redis-exposed →

References

Cite this record

unauth.dev advisory UNAUTH-2026-0021 — published 2026-08 · CC-BY 4.0

Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0021. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.