CVE-2026-106038
Deferred Deferred - Pending Action

Authentication Bypass in Mooncake Store Leading to Data Deletion

Vulnerability report for CVE-2026-106038, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VulnCheck

Description

Mooncake Store master through 0.3.13.post1 contains a missing authentication vulnerability that allows unauthenticated attackers to force-delete any object via Remove, RemoveByRegex, RemoveAll and BatchRemove on the coro_rpc port. Attackers can send forged requests with the force flag set to bypass lease checks, wipe keys matching any regex, or clear the entire store, causing cache loss and request failures.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kvcache-ai Mooncake 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Mooncake Store master through 0.3.13.post1 allows unauthenticated attackers to delete any object by exploiting missing authentication checks on the coro_rpc port. Attackers can send forged requests with the force flag enabled to bypass lease checks, wipe keys using regex patterns, or clear the entire store, leading to cache loss and service disruptions.

Detection Guidance

Check if the Mooncake Store master service is running on the coro_rpc port. Use netstat or ss to identify listening ports. Look for unauthenticated requests to endpoints like Remove, RemoveByRegex, RemoveAll, or BatchRemove with the force flag set.

Impact Analysis

This vulnerability can cause data loss by allowing attackers to delete critical cache entries or entire datasets. It may lead to service outages, unauthorized data removal, and potential denial-of-service conditions affecting applications relying on Mooncake Store for caching or storage.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR or HIPAA by enabling unauthorized data deletion or loss of integrity. Organizations may face penalties for failing to protect sensitive data, especially if the cache contained regulated information like personal or health records.

Mitigation Strategies

Upgrade Mooncake Store master to a version beyond 0.3.13.post1. Restrict network access to the coro_rpc port using firewalls. Implement authentication for RPC endpoints. Monitor logs for suspicious Remove operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106038. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart