CVE-2026-105049: Zilliz Attu
Medium severity, CVSS 5.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.
Affected products
- Zilliz Attu: from 2.6.5, before 3.0.0 (fixed in 3.0.0)
Published 2026-10-02. Last modified 2026-10-06.