Intel

AIKIDO-2026-10039

github.com/milvus-io/milvus/pkg/v2 is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jan 14, 2026

71

High Risk

This Affects:

GOgithub.com/milvus-io/milvus/pkg/v2
2.0.0 - 2.6.7
Fixed in 2.6.8
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to incorrect RBAC authorization behavior where etcd prefix queries can match entries with similar prefixes, potentially causing roles or grants to be resolved for the wrong user or entity. For example, when querying roles for user "admin", it could mistakenly return roles belonging to "admin2".

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/milvus-io/milvus/pkg/v2 is vulnerable to Information Disclosure in versions 2.0.0 - 2.6.7.

How to fix this

Upgrade the github.com/milvus-io/milvus/pkg/v2 library to the patch version.