Executive brief
Milvus, an open-source vector database, contains a flaw in how it manages user permissions. The system uses a weak identification method for security roles that can lead to 'collisions,' where two different roles are mistakenly treated as the same. In practice, this could allow a user with limited access to gain the permissions of a more privileged role, potentially leading to unauthorized data access or modification.
Technical details
A vulnerability exists in the Milvus RBAC (Role-Based Access Control) implementation within 'internal/metastore/kv/rootcoord/kv_catalog.go'. The system generates 'grantee-id' values by truncating MD5 hashes to 64 bits (16 hex characters). This short identifier length significantly increases the probability of hash collisions. An attacker with local access to the metadata store (e.g., etcd) or the ability to influence role/object names could cause two different authorization relationships to share the same identifier. This results in cross-role privilege forgery, where a victim role resolves the privilege subtree of a donor role. The issue is addressed in patch 3d932f1c3e065351c4440c27abe1e6479752544d.
Affected products
- milvus-io milvus < 0.10.3-0.20260602041816-3d932f1c3e06
Timeline
- 2026-06-04: advisory
- 2026-06-04: disclosed
- 2026-07-15: patched