CVE-2026-106040
Received Received - Intake

Unauthenticated Disk Replica Eviction in Mooncake Store

Vulnerability report for CVE-2026-106040, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VulnCheck

Description

Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to erase any object's disk replica via EvictDiskReplica and BatchEvictDiskReplica. Attackers reaching the coro_rpc master port can evict DISK replicas across all tenants, deleting objects whose only remaining replica is on disk.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kvcache-ai Mooncake 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing authorization flaw in Mooncake Store master through version 0.3.13.post1. It allows unauthenticated attackers to erase disk replicas of any object via EvictDiskReplica and BatchEvictDiskReplica RPCs. Attackers can reach the coro_rpc master port to delete DISK replicas across all tenants, potentially removing objects that only have a disk-based replica remaining.

Detection Guidance

Check if the Mooncake Store master service is running on the default coro_rpc port (50051) without authentication. Use network scanning tools like nmap to detect open ports and services. Example command: nmap -p 50051 <target-ip>. Inspect RPC calls to EvictDiskReplica and BatchEvictDiskReplica functions for unauthorized access attempts.

Impact Analysis

Unauthenticated attackers could delete critical data by removing disk replicas, leading to permanent data loss if the disk replica is the last remaining copy. This could disrupt services relying on Mooncake Store for storage, especially in multi-tenant environments where data isolation is essential.

Compliance Impact

This vulnerability could lead to unauthorized data deletion or loss, violating data integrity and availability requirements in GDPR and HIPAA. Compliance may be impacted if sensitive or protected data is permanently lost due to the lack of proper authorization checks.

Mitigation Strategies

Immediately restrict access to the coro_rpc master port (50051) using firewalls or network policies. Disable or update the Mooncake Store master to a patched version if available. Monitor for unauthorized RPC calls to EvictDiskReplica and BatchEvictDiskReplica functions. Consider disabling disk replica eviction if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106040. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart