Missing Authorization Vulnerability in Mooncake Store by KVCACHE
CVE-2026-106039

6.9MEDIUM

Key Information:

Vendor

Kvcache-ai

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106039?

The Mooncake Store software exhibits a missing authorization vulnerability allowing unauthorized attackers to manipulate replication tasks through the coro_rpc port. This flaw enables attackers to invoke operations such as creating, stealing, and manipulating replication tasks using victim client UUIDs exposed via the QueryTask function. Exploiting this vulnerability could allow execution of tasks that appear legitimate, leading to unauthorized data manipulation and potential data integrity issues.

Affected Version(s)

Mooncake 0 <= 0.3.13.post1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mingkai Yu
Jiajia Liu
.