Sceawere
Vulnerability Detail
CVE-2026-106041UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Mooncake Store Missing Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 11h ago
- Vendor
- kvcache-ai
- Product
- Mooncake
- Attack Type
- Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to inject completed LOCAL_DISK replicas through the NotifyOffloadSuccess RPC. Attackers can mount a local disk segment with a self-chosen client UUID, then attach replicas pointing at attacker-controlled endpoints to serve poisoned disk-tier reads and fake key existence.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-06T14:17:43.983Z",
"pubdate": "2026-10-06T14:17:43.983Z",
"executiveSummary": "Mooncake Store versions up to and including 0.3.13.post1 are susceptible to a critical missing authorization vulnerability within the NotifyOffloadSuccess RPC mechanism.\nThe vulnerability permits unauthenticated remote attackers to bypass authorization controls, enabling the injection of arbitrary LOCAL_DISK replicas into the system.\nBy manipulating the offload notification process, an attacker can influence the storage metadata, leading to poisoned data reads and the falsification of key existence within the storage architecture.\nThis flaw presents significant integrity and availability risks, as it allows for the subversion of disk-tier read operations and the potential corruption of downstream application logic reliant on Mooncake Store data.\nNo authentication is required for exploitation, granting any attacker with network visibility to the RPC interface the capability to execute this unauthorized state mutation.",
"technicalDetails": "The root cause of this vulnerability lies in the lack of identity verification and authorization checks within the NotifyOffloadSuccess RPC function in Mooncake Store master through 0.3.13.post1.\nThe system fails to validate the origin or the legitimacy of the notification requests received, allowing an unauthenticated entity to interact with the internal replica management logic.\nThe exploitation flow initiates when an attacker issues a crafted NotifyOffloadSuccess RPC call to the vulnerable component.\nBy specifying a self-chosen client UUID, the attacker successfully registers a malicious LOCAL_DISK segment within the Mooncake Store ecosystem.\nSubsequently, the attacker attaches replicas that point to attacker-controlled remote endpoints rather than legitimate storage backends.\nBecause the system accepts these fabricated replicas as valid, subsequent read operations directed at the poisoned disk-tier will be redirected to the attacker-controlled endpoints.\nThis allows the attacker to serve arbitrary data in response to read requests, facilitating a data poisoning attack that masquerades as legitimate storage output.\nFurthermore, the attacker can manipulate the replica metadata to confirm the existence of specific keys that do not actually exist within the valid storage state, or conversely, conceal existing data.\nThe vulnerability is exposed over the network, and because the RPC interface does not enforce mutual TLS or authentication headers for the NotifyOffloadSuccess operation, the exploitation surface is broad for any entity capable of communicating with the store's management port.\nPost-exploitation, the impact is severe; the attacker effectively gains control over the integrity of data served from the disk-tier, leading to potential cache poisoning, application logic errors, or the exfiltration of system behaviors governed by the manipulated storage state."
}