Sceawere

Vulnerability Detail

CVE-2026-106040UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Mooncake Store Missing Authorization Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
11h ago
Vendor
kvcache-ai
Product
Mooncake
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Attack Complexity
LOW

Narrative and Response

Description

Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to erase any object's disk replica via EvictDiskReplica and BatchEvictDiskReplica. Attackers reaching the coro_rpc master port can evict DISK replicas across all tenants, deleting objects whose only remaining replica is on disk.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-10-06T14:17:43.833Z",
  "pubdate": "2026-10-06T14:17:43.833Z",
  "executiveSummary": "Mooncake Store versions up to and including 0.3.13.post1 are susceptible to a critical missing authorization vulnerability. This flaw resides within the master node's RPC interface, specifically affecting functions responsible for disk replica management. By failing to validate authentication or authorization tokens, the application allows unauthenticated, remote attackers to trigger the eviction of disk replicas across all multi-tenant environments.\nThe vulnerability poses a severe risk to data availability and integrity. Successful exploitation grants an attacker the capability to delete objects by purging their sole disk-based replicas. This can lead to permanent data loss if the disk replica is the only surviving copy of an object within the storage architecture. The exploit requires network connectivity to the coro_rpc master port, necessitating that the management interface be accessible to unauthorized entities. Given the potential for widespread data destruction across all tenants, this issue necessitates immediate remediation through access control implementation or network segmentation.",
  "technicalDetails": "The vulnerability stems from an improper implementation of access control within the Mooncake Store master node, which utilizes the coro_rpc protocol for inter-process and administrative communication. The master node exposes specific RPC functions, namely EvictDiskReplica and BatchEvictDiskReplica, intended for storage lifecycle management. However, these functions do not implement the necessary authentication or authorization checks to verify the requester's identity or permissions before executing the requested disk eviction operations.\nThe attack flow begins with the adversary identifying an exposed coro_rpc master port, typically accessible via the network. Once a connection is established, the attacker can transmit malformed or direct RPC calls targeting the EvictDiskReplica or BatchEvictDiskReplica functions. Because the master service assumes that internal requests are inherently trusted, it processes these commands without verifying the source. By specifying the target object identifiers, the attacker instructs the storage engine to remove the physical disk replicas associated with the provided objects.\nThe impact is significant because Mooncake Store manages data redundancy through various storage media, including disk and potential other tiers. If an object's redundancy configuration results in the disk replica being the final or only available copy within the cluster, the execution of the eviction command triggers a permanent deletion of that data. This process can be automated or scaled across all tenants residing on the affected storage system by iterating through object identifiers or utilizing the BatchEvictDiskReplica function for bulk deletions.\nThe root cause is a failure to enforce mandatory authorization at the API endpoint level for administrative commands. While the system expects these calls to originate from authorized components, the lack of cryptographically signed requests or session-based validation allows any actor capable of reaching the coro_rpc port to masquerade as a privileged administrator. There are no privilege requirements for the attacker, as the interface treats all unauthenticated callers with the authority to modify the storage state.\nAffected versions include Mooncake Store master through 0.3.13.post1. Exploitation occurs entirely in the application layer, requiring no prior knowledge of credentials or secondary vulnerabilities. The resulting post-exploitation impact includes denial-of-service via data unavailability and destructive unauthorized modification of stored data, impacting all tenants managed by the compromised master node."
}
CVE-2026-106040: Mooncake Store Missing Authorization Vulnerability (HIGH Severity, CVSS: 8.2) | Sceawere