Sceawere
Vulnerability Detail
CVE-2026-106039UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Mooncake Store Authorization Bypass Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 11h ago
- Vendor
- kvcache-ai
- Product
- Mooncake
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to create, steal, and falsely complete replication tasks via the coro_rpc port. Attackers can invoke CreateCopyTask, CreateMoveTask, FetchTasks, and MarkTaskToComplete with victim client UUIDs disclosed by QueryTask to hijack task queues and record replication that never occurred.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-06T14:17:43.660Z",
"pubdate": "2026-10-06T14:17:43.660Z",
"executiveSummary": "Mooncake Store versions through 0.3.13.post1 are susceptible to a critical missing authorization vulnerability within the coro_rpc interface.\nThe vulnerability permits unauthenticated remote attackers to interact directly with the task replication subsystem, bypassing existing security controls.\nBy leveraging this flaw, unauthorized actors can manipulate task queues by creating, stealing, or falsely completing replication tasks using victim-specific identifiers.\nThe impact includes the potential for data integrity compromise, where attackers can falsely signal the completion of replication tasks, and unauthorized task hijacking, which can disrupt backend operations.\nSuccessful exploitation requires no prior authentication, significantly lowering the barrier to attack and posing substantial operational risks to environments utilizing the coro_rpc service.\nThis vulnerability highlights a fundamental failure in access control validation, allowing arbitrary invocation of sensitive RPC functions that were intended to be restricted.",
"technicalDetails": "The root cause of this vulnerability lies in the lack of identity verification and authorization checks within the Mooncake Store coro_rpc implementation. The service exposes a suite of administrative functions—specifically CreateCopyTask, CreateMoveTask, FetchTasks, and MarkTaskToComplete—without validating the provenance or authorization level of the requesting entity.\nThe attack flow begins with the exploitation of the QueryTask function. Since the RPC interface does not enforce authentication, an attacker can query the system to enumerate valid client UUIDs. These UUIDs act as unique identifiers for task queues and specific client contexts within the replication engine.\nOnce the attacker obtains a list of valid client UUIDs, they can initiate a sequence of unauthorized RPC calls to manipulate task states. By invoking CreateCopyTask or CreateMoveTask, an attacker can inject malicious replication instructions into the task queue assigned to a specific victim client.\nFurthermore, the attacker can leverage the MarkTaskToComplete function to falsely validate the completion of non-existent or malicious tasks, thereby poisoning the audit logs and state synchronization mechanisms of the Mooncake Store. This results in the system incorrectly recording that data replication has occurred successfully when no such process was initiated by the legitimate host.\nThe vulnerable component is the coro_rpc service, which facilitates inter-process communication for task management. Because this service is exposed via network sockets without access controls, the attack surface is globally accessible to any actor capable of reaching the RPC port. The absence of cryptographically secure session management or source-IP filtering exacerbates the severity of the flaw.\nPost-exploitation impact includes the hijacking of replication workflows, potential data corruption due to misaligned task states, and the ability to perform persistent interference with system orchestration. The ability to manipulate task queues without authentication effectively grants the attacker control over the logical flow of data replication within the Mooncake Store environment."
}