CVE-2026-69111: Milvus 2.6.22, 3.0.0 Unauthenticated Denial of Service via /management/stop
Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP GET request to the management server on port 9091. Attackers can exploit the unprotected /management/stop endpoint, which bypasses REST API authentication middleware, by supplying a 'role' parameter to shut down the proxy, datanode, or querynode components, resulting in denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-69111?
CVE-2026-69111 has a high severity rating of 7.5.
How do I fix CVE-2026-69111?
To mitigate CVE-2026-69111, upgrade Milvus to version 3.0.1 or later.
What does CVE-2026-69111 affect?
CVE-2026-69111 affects Milvus versions 2.6.22 and 3.0.0, allowing unauthenticated denial of service.
Can CVE-2026-69111 be exploited remotely?
Yes, CVE-2026-69111 can be exploited remotely through a crafted HTTP GET request.
What component of Milvus is vulnerable in CVE-2026-69111?
The unprotected /management/stop endpoint of the Milvus management server is vulnerable in CVE-2026-69111.