PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-10814 milvus-io CVE debrief

A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file internal/metastore/kv/rootcoord/kv_catalog.go of the component Grantee ID Hash Handler. The manipulation leads to use of weak hash. The attack needs to be performed locally. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been disclosed to the public and may be used.

Vendor
milvus-io
Product
milvus
CVSS
LOW 1.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-04
Original CVE updated
2026-07-22
Advisory published
2026-06-04
Advisory updated
2026-07-22

Who should care

Users of Milvus up to version 2.6.13

Technical summary

The vulnerability is caused by the use of a weak hash in the Grantee ID Hash Handler. The affected code is located in the file internal/metastore/kv/rootcoord/kv_catalog.go.

Defensive priority

Low

Recommended defensive actions

  • Apply the patch with identifier 3d932f1c3e065351c4440c27abe1e6479752544d.

Evidence notes

The CVSS score for this vulnerability is 1.1, indicating a low severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-10814 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-10814

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-10814 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-10814

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.