Description
Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.
Published: 2026-10-02
Score: 5.8 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated Proxying of External Requests
Action: Patch
AI Analysis

Impact

Zilliz Attu before version 3.0.0 features a Playground that can forward arbitrary HTTP and HTTPS requests to any public URL without requiring authentication. This absence of access control allows an attacker who can reach the Playground interface to send requests to external sites, potentially enabling data exfiltration or malicious traffic redirection. The vulnerability is a missing authentication weakness (CWE-306) and does not provide direct code execution but can facilitate reconnaissance and proxy-based attacks.

Affected Systems

The issue affects the Zilliz Attu product for all releases earlier than 3.0.0. No specific sub‑versions are listed, so any deployment of Attu below 3.0.0 is susceptible.

Risk and Exploitability

The CVSS score of 5.8 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation at present. However, because the Playground requires no authentication, an attacker with network access to the Attu instance can abuse the proxy functionality. The exploitation is straightforward via the web interface, making it relatively easy to abuse if the service is exposed.

Generated by OpenCVE AI on October 2, 2026 at 23:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to Attu 3.0.0 or later to eliminate the unauthenticated proxy feature
  • Disable or remove the Playground component until a patch is applied
  • Configure network access controls or firewall rules to prevent external users from reaching the Attu Playground interface

Generated by OpenCVE AI on October 2, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Proxying via Zilliz Attu Playground

Fri, 02 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
Description Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-02T22:14:36.181Z

Reserved: 2026-10-02T22:14:35.487Z

Link: CVE-2026-105049

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T23:16:57.943

Modified: 2026-10-02T23:16:57.943

Link: CVE-2026-105049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T23:30:10Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function