Sceawere

Vulnerability Detail

CVE-2026-106038UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Mooncake Store Unauthenticated Data Destruction

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
11h ago
Vendor
kvcache-ai
Product
Mooncake
Attack Type
Missing Authentication for Critical Function
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Attack Complexity
LOW

Narrative and Response

Description

Mooncake Store master through 0.3.13.post1 contains a missing authentication vulnerability that allows unauthenticated attackers to force-delete any object via Remove, RemoveByRegex, RemoveAll and BatchRemove on the coro_rpc port. Attackers can send forged requests with the force flag set to bypass lease checks, wipe keys matching any regex, or clear the entire store, causing cache loss and request failures.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-10-06T14:17:42.420Z",
  "pubdate": "2026-10-06T14:17:42.420Z",
  "executiveSummary": "Mooncake Store versions through 0.3.13.post1 are susceptible to a critical missing authentication vulnerability within the coro_rpc interface.\nThis vulnerability allows unauthenticated, remote attackers to execute arbitrary deletion operations on the key-value store, resulting in complete data loss and service unavailability.\nThe flaw stems from the failure of the RPC interface to validate the identity of clients before processing destructive commands.\nAttackers can leverage this to invoke high-impact functions such as Remove, RemoveByRegex, RemoveAll, and BatchRemove. By manipulating the 'force' flag within these requests, an adversary can circumvent internal lease verification mechanisms, effectively neutralizing security controls designed to prevent unauthorized key deletion.\nThe risk implication is severe, as the vulnerability enables full cache wiping or targeted data removal, which leads to immediate request failures and significant operational disruption.\nExploitation requires no prior authentication and can be performed over the network via the exposed coro_rpc port, making it a high-priority risk for any deployment using default configurations.",
  "technicalDetails": "The vulnerability resides within the Mooncake Store RPC architecture, specifically the handling of requests directed toward the coro_rpc service. The root cause is the absence of an authentication handshake or authorization check for incoming RPC messages. Because the service does not verify the provenance or legitimacy of the caller, any entity capable of establishing a network connection to the coro_rpc port can issue privileged commands.\nThe core of the issue involves how the RPC interface processes deletion primitives: Remove, RemoveByRegex, RemoveAll, and BatchRemove. These functions are designed to manipulate the data store, and the application logic includes a 'force' parameter intended to manage complex concurrency scenarios or lease locks. In the vulnerable versions, the RPC handler accepts this 'force' parameter from the unauthenticated input stream without validating the user's authority to override existing lease controls.\nAn attack flow initiates by the adversary establishing a TCP connection to the Mooncake Store's coro_rpc endpoint. Once connected, the attacker serializes a forged RPC request targeting one of the susceptible deletion functions. By crafting a payload that explicitly sets the 'force' flag to true, the attacker bypasses the application's internal check-and-set logic. For example, if 'RemoveByRegex' is invoked with a wildcard pattern and the 'force' flag set, the storage backend processes the request as a privileged administrative action, purging all matching keys regardless of their current lease state.\nThe technical impact is total control over the data store lifecycle. An attacker can execute a 'RemoveAll' command to perform a complete wipe of the cache, or utilize 'RemoveByRegex' to surgically delete specific namespaces or key prefixes, causing application-level service degradation or total failure. Because this occurs at the RPC layer, the data is removed before any application logic can intervene. The vulnerability affects all Mooncake Store deployments using versions 0.3.13.post1 and earlier that expose the coro_rpc port to untrusted network segments. Post-exploitation results in a permanent state of cache inconsistency, forcing downstream applications to undergo expensive, potentially failing, cache-miss recovery cycles."
}
CVE-2026-106038: Mooncake Store Unauthenticated Data Destruction (HIGH Severity, CVSS: 8.2) | Sceawere