CVE-2019-11466: Couchbase Server
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in version 6.0.1 and now requires valid credentials to access.
Affected products
- Couchbase Couchbase Server: version 5.5.0 only; version 6.0.0 only
Published 2019-09-10. Last modified 2026-06-17.