{"id":"CVE-2026-106039","title":"Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to create, steal, and falsely complete replication tasks via the coro_rpc port","summary":"Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to create, steal, and falsely complete replication tasks via the coro_rpc port. Attackers can invoke CreateCo…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-862"],"vendor":"kvcache-ai","product":"Mooncake","affected":["Mooncake <= 0.3.13.post1"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T16:17:07.017","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106039","references":[{"url":"https://github.com/kvcache-ai/Mooncake","label":"disclosure@vulncheck.com"},{"url":"https://github.com/kvcache-ai/Mooncake/blob/719735896c86b56fabec6cf3e825fb2ea640597a/mooncake-store/src/master_service.cpp#L12060-L12120","label":"disclosure@vulncheck.com"},{"url":"https://github.com/kvcache-ai/Mooncake/blob/719735896c86b56fabec6cf3e825fb2ea640597a/mooncake-store/src/task_manager.cpp#L113-L135","label":"disclosure@vulncheck.com"},{"url":"https://github.com/kvcache-ai/Mooncake/issues/4475","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/mooncake-store-through-0.3.13-post1-missing-authorization-in-replication-task-rpc","label":"disclosure@vulncheck.com"},{"url":"https://github.com/kvcache-ai/Mooncake/issues/4475","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-10-06T15:32:13.485050Z"},"ingestedAt":"2026-10-06T15:01:49.289Z","slug":"CVE-2026-106039","body":"## Overview\n\nMooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to create, steal, and falsely complete replication tasks via the coro_rpc port. Attackers can invoke CreateCopyTask, CreateMoveTask, FetchTasks, and MarkTaskToComplete with victim client UUIDs disclosed by QueryTask to hijack task queues and record replication that never occurred.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":216522,"id":"CVE-2026-106039","ts":1791302932922,"field":"exploit_available","old":"false","new":"true"}]}