Missing Authorization Vulnerability in Mooncake Store by kvcache-ai
CVE-2026-106040
8.8HIGH
What is CVE-2026-106040?
The Mooncake Store, prior to version 0.3.13.post1, contains a significant vulnerability that allows unauthenticated attackers to delete any object's disk replicas through the EvictDiskReplica and BatchEvictDiskReplica features. By accessing the coro_rpc master port, these attackers can erase disk replicas across multiple tenants, jeopardizing the integrity and availability of essential data.
Affected Version(s)
Mooncake 0 <= 0.3.13.post1
