Unauthenticated Object Deletion in Mooncake Store by KVCache
CVE-2026-106038
8.8HIGH
What is CVE-2026-106038?
The Mooncake Store master version up to 0.3.13.post1 is exposed to a missing authentication vulnerability that enables attackers without authentication to issue remove commands via the coro_rpc port. By exploiting this weakness, attackers can send crafted requests with the force flag enabled, thereby bypassing lease checks. This can lead to unauthorized deletion of keys based on regular expressions or even to the complete clearing of the data store. Such actions can result in significant data loss and disrupt the normal operation of the cache service, leading to request failures.
Affected Version(s)
Mooncake 0 <= 0.3.13.post1
