← Back to CVE List
CVE-2026-106039NVD
Vulnerability Summary
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to create, steal, and falsely complete replication tasks via the coro_rpc port. Attackers can invoke CreateCopyTask, CreateMoveTask, FetchTasks, and MarkTaskToComplete with victim client UUIDs disclosed by QueryTask to hijack task queues and record replication that never occurred.
CVSS v4.0 Base Metrics — Score 6.9 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)Low
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 6.5 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityLow
AvailabilityLow
Affected & Patched Versions
- kvcache-ai Mooncake <= 0.3.13.post1
- kvcache-ai Mooncake 0.3.13.post1
External References
- https://github.com/kvcache-ai/Mooncake/issues/4475
- https://github.com/kvcache-ai/Mooncake/blob/719735896c86b56fabec6cf3e825fb2ea640597a/mooncake-store/src/master_service.cpp#L12060-L12120
- https://github.com/kvcache-ai/Mooncake/blob/719735896c86b56fabec6cf3e825fb2ea640597a/mooncake-store/src/task_manager.cpp#L113-L135
- https://github.com/kvcache-ai/Mooncake
- https://www.vulncheck.com/advisories/mooncake-store-through-0.3.13-post1-missing-authorization-in-replication-task-rpc