CVE-2026-106041
Deferred Deferred - Pending Action

Missing Authorization in Mooncake Store Allows Local Disk Replica Injection

Vulnerability report for CVE-2026-106041, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VulnCheck

Description

Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to inject completed LOCAL_DISK replicas through the NotifyOffloadSuccess RPC. Attackers can mount a local disk segment with a self-chosen client UUID, then attach replicas pointing at attacker-controlled endpoints to serve poisoned disk-tier reads and fake key existence.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kvcache-ai Mooncake 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Mooncake Store master through 0.3.13.post1 allows unauthenticated attackers to inject completed LOCAL_DISK replicas via the NotifyOffloadSuccess RPC. Attackers can mount a local disk segment with a chosen client UUID and attach replicas pointing to attacker-controlled endpoints. This enables serving poisoned disk-tier reads and fake key existence.

Impact Analysis

Unauthenticated attackers could manipulate data reads and falsify key existence, leading to incorrect or malicious data being served. This could result in data corruption, unauthorized access, or denial of service if the system relies on accurate disk-tier reads and key verification.

Compliance Impact

This vulnerability could violate compliance requirements for data integrity and access controls. GDPR requires data accuracy and protection, while HIPAA mandates secure access to health information. Exploitation could lead to unauthorized data access or integrity breaches, risking non-compliance.

Mitigation Strategies

Update Mooncake Store to the latest version (0.3.13.post1 or later) to address the missing authorization vulnerability. Ensure proper access controls are enforced for RPC endpoints and restrict unauthenticated NotifyOffloadSuccess RPC calls.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106041. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart