Unauthenticated Object Deletion in Mooncake Store by KVCache
CVE-2026-106038

8.8HIGH

Key Information:

Vendor

Kvcache-ai

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106038?

The Mooncake Store master version up to 0.3.13.post1 is exposed to a missing authentication vulnerability that enables attackers without authentication to issue remove commands via the coro_rpc port. By exploiting this weakness, attackers can send crafted requests with the force flag enabled, thereby bypassing lease checks. This can lead to unauthorized deletion of keys based on regular expressions or even to the complete clearing of the data store. Such actions can result in significant data loss and disrupt the normal operation of the cache service, leading to request failures.

Affected Version(s)

Mooncake 0 <= 0.3.13.post1

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mingkai Yu
Jiajia Liu
.