← Vulnerability feed

Vulnerability record · CVE-2021-29442 · published 27 April 2021

CVE-2021-29442: Nacos ConfigOpsController derby endpoint missing authentication

Alibaba · Nacos

In Nacos before 1.4.1, the ConfigOpsController exposes a /derby endpoint that lacks the @Secured annotation applied to /data/remove, allowing unauthenticated access to management operations such as querying or wiping the embedded database. The issue only affects installations using embedded Derby storage, not those backed by external databases like MySQL.

7.5 CVSS 3.1 High EPSS 66% · top 0.8% CWE-306 · Missing authentication for critical function
7.5CVSS 3.1 base score, v2 5.0
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform management operations like querying the database or even wiping it out. While the /data/remove endpoint is properly protected with the @Secured annotation, the /derby endpoint is not protected and can be openly accessed by unauthenticated users. These endpoints are only valid when using embedded storage (derby DB) so this issue should not affect those installations using external storage (e.g. mysql)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 7.5 with no authentication required, public exploit references, and a very high EPSS percentile make this a high-priority exposure for affected embedded-storage deployments.

What it is

In Nacos before 1.4.1, the ConfigOpsController exposes a /derby endpoint that lacks the @Secured annotation applied to /data/remove, allowing unauthenticated access to management operations such as querying or wiping the embedded database. The issue only affects installations using embedded Derby storage, not those backed by external databases like MySQL.

Impact

An unauthenticated attacker can read data from the embedded Derby database and potentially destroy it, causing loss of configuration and service-discovery data. The CVSS vector rates confidentiality impact as high with no integrity or availability impact recorded.

Attack surface

Reachable over the network via HTTP against the Nacos ConfigOpsController /derby endpoint; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Only deployments using embedded Derby storage are exposed.

Exploitation

Not listed in CISA KEV, but EPSS probability is 0.6663 (99.25th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade Nacos to version 1.4.1 or later, which contains the patch referenced in PR 4517.
  • If immediate upgrade is not possible, restrict network access to the ConfigOpsController endpoints so only trusted administrative hosts can reach them.
  • Migrate from embedded Derby storage to an external database such as MySQL, which the advisory states is not affected.
  • Audit Nacos deployments for embedded Derby usage and confirm whether the /derby endpoint is externally reachable.
  • Monitor for unauthorized access attempts to /derby and other ConfigOpsController paths.

Detection

  • Search HTTP access logs for requests to the /derby endpoint on Nacos servers, especially from unexpected source IPs.
  • Alert on unauthenticated requests to ConfigOpsController management paths.
  • Monitor for unexpected database read or wipe activity in embedded Derby-backed Nacos instances.
  • Inventory Nacos instances and flag any running versions below 1.4.1 with embedded storage.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/advisories/GHSA-36hp-jr8h-556f ExploitThird Party Advisory
https://github.com/alibaba/nacos/issues/4463 ExploitThird Party Advisory
https://github.com/alibaba/nacos/pull/4517 PatchThird Party Advisory
https://github.com/advisories/GHSA-36hp-jr8h-556f ExploitThird Party Advisory
https://github.com/alibaba/nacos/issues/4463 ExploitThird Party Advisory
https://github.com/alibaba/nacos/pull/4517 PatchThird Party Advisory

Track CVE-2021-29442 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-29441Nacos AuthFilter authentication bypass via spoofed User-AgentNacos before 1.4.1 contains a backdoor in the AuthFilter servlet filter that lets requests bypass authentication checks when authentication is enable…EPSS 83%analysed8.8CVE-2021-43116Alibaba nacos improper authentication vulnerabilityAn Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and t…EPSS 7.5%6.1CVE-2021-44667Alibaba nacos cross-site scripting vulnerabilityA Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters.EPSS 0.83%5.3CVE-2020-19676Alibaba nacos vulnerabilityNacos 1.1.4 is affected by: Incorrect Access Control. An environment can be set up locally to get the service details interface. Then other Nacos ser…EPSS 1.4%8.8CVE-2026-67277MikroTik RouterOS btest missing authentication leaks kernel memory and crashes kernelRouterOS accepts a "related" btest connection before the primary session is authenticated, letting an unauthenticated client start an IPv4 UDP test. …KEVEPSS 1.6%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed9.3CVE-2026-72529TrueConf Server missing authentication allows remote script executionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier expose an undocumented function on port 4307/TCP …KEVEPSS 1.5%analysed9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed

Source: NIST National Vulnerability Database (record CVE-2021-29442), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.