A vulnerability has been found in Zilliz Attu up to 2.6.4 and classified as critical. This issue affects some unknown processing of the component Playground. Performing a manipulation results in server-side request forgery. This vulnerability is identified as CVE-2026-105048. The attack can be initiated remotely. There is not any exploit available. The affected component should be upgraded.
Exploit
CVE-2026-105048
VulDB
Apply vendor security patch