CVE-2026-106039: Kvcache-Ai Mooncake
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to create, steal, and falsely complete replication tasks via the coro_rpc port. Attackers can invoke CreateCopyTask, CreateMoveTask, FetchTasks, and MarkTaskToComplete with victim client UUIDs disclosed by QueryTask to hijack task queues and record replication that never occurred.
Affected products
- Kvcache-Ai Mooncake: up to and including 0.3.13.post1
Published 2026-10-06. Last modified 2026-10-06.