CVE-2026-106039: Kvcache-Ai Mooncake

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to create, steal, and falsely complete replication tasks via the coro_rpc port. Attackers can invoke CreateCopyTask, CreateMoveTask, FetchTasks, and MarkTaskToComplete with victim client UUIDs disclosed by QueryTask to hijack task queues and record replication that never occurred.

Affected products

  • Kvcache-Ai Mooncake: up to and including 0.3.13.post1

Published 2026-10-06. Last modified 2026-10-06.