CVE-2026-105049
5.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Summary
Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Zilliz | Attu | 2.6.5 < 3.0.0 | affected |
| Zilliz | Attu | 0 < 2.6.5 | unknown |
Weaknesses
- CWE-306: CWE-306 Missing Authentication for Critical Function
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.