CVE-2026-105049: Medium severity Zilliz Attu vulnerability
Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any network-reachable user can exploit the Playground feature because it does not require authentication. The feature can proxy arbitrary HTTP and HTTPS requests to public-internet URLs.
Is a default deployment affected?
The provided information identifies the Playground feature as unauthenticated and does not describe any additional configuration requirement. Deployments of Zilliz Attu before 3.0.0 that expose this feature are affected.
What is the immediate mitigation if upgrading is not possible?
Restrict access to Attu so untrusted users cannot reach the unauthenticated Playground feature. The available information does not provide a more specific configuration-based workaround.