Sceawere
Vulnerability Detail
CVE-2026-106038UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Mooncake Store Unauthenticated Data Destruction
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 11h ago
- Vendor
- kvcache-ai
- Product
- Mooncake
- Attack Type
- Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Mooncake Store master through 0.3.13.post1 contains a missing authentication vulnerability that allows unauthenticated attackers to force-delete any object via Remove, RemoveByRegex, RemoveAll and BatchRemove on the coro_rpc port. Attackers can send forged requests with the force flag set to bypass lease checks, wipe keys matching any regex, or clear the entire store, causing cache loss and request failures.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-10-06T14:17:42.420Z",
"pubdate": "2026-10-06T14:17:42.420Z",
"executiveSummary": "Mooncake Store versions through 0.3.13.post1 are susceptible to a critical missing authentication vulnerability within the coro_rpc interface.\nThis vulnerability allows unauthenticated, remote attackers to execute arbitrary deletion operations on the key-value store, resulting in complete data loss and service unavailability.\nThe flaw stems from the failure of the RPC interface to validate the identity of clients before processing destructive commands.\nAttackers can leverage this to invoke high-impact functions such as Remove, RemoveByRegex, RemoveAll, and BatchRemove. By manipulating the 'force' flag within these requests, an adversary can circumvent internal lease verification mechanisms, effectively neutralizing security controls designed to prevent unauthorized key deletion.\nThe risk implication is severe, as the vulnerability enables full cache wiping or targeted data removal, which leads to immediate request failures and significant operational disruption.\nExploitation requires no prior authentication and can be performed over the network via the exposed coro_rpc port, making it a high-priority risk for any deployment using default configurations.",
"technicalDetails": "The vulnerability resides within the Mooncake Store RPC architecture, specifically the handling of requests directed toward the coro_rpc service. The root cause is the absence of an authentication handshake or authorization check for incoming RPC messages. Because the service does not verify the provenance or legitimacy of the caller, any entity capable of establishing a network connection to the coro_rpc port can issue privileged commands.\nThe core of the issue involves how the RPC interface processes deletion primitives: Remove, RemoveByRegex, RemoveAll, and BatchRemove. These functions are designed to manipulate the data store, and the application logic includes a 'force' parameter intended to manage complex concurrency scenarios or lease locks. In the vulnerable versions, the RPC handler accepts this 'force' parameter from the unauthenticated input stream without validating the user's authority to override existing lease controls.\nAn attack flow initiates by the adversary establishing a TCP connection to the Mooncake Store's coro_rpc endpoint. Once connected, the attacker serializes a forged RPC request targeting one of the susceptible deletion functions. By crafting a payload that explicitly sets the 'force' flag to true, the attacker bypasses the application's internal check-and-set logic. For example, if 'RemoveByRegex' is invoked with a wildcard pattern and the 'force' flag set, the storage backend processes the request as a privileged administrative action, purging all matching keys regardless of their current lease state.\nThe technical impact is total control over the data store lifecycle. An attacker can execute a 'RemoveAll' command to perform a complete wipe of the cache, or utilize 'RemoveByRegex' to surgically delete specific namespaces or key prefixes, causing application-level service degradation or total failure. Because this occurs at the RPC layer, the data is removed before any application logic can intervene. The vulnerability affects all Mooncake Store deployments using versions 0.3.13.post1 and earlier that expose the coro_rpc port to untrusted network segments. Post-exploitation results in a permanent state of cache inconsistency, forcing downstream applications to undergo expensive, potentially failing, cache-miss recovery cycles."
}