CVE-2026-106041: Kvcache-Ai Mooncake

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to inject completed LOCAL_DISK replicas through the NotifyOffloadSuccess RPC. Attackers can mount a local disk segment with a self-chosen client UUID, then attach replicas pointing at attacker-controlled endpoints to serve poisoned disk-tier reads and fake key existence.

Affected products

  • Kvcache-Ai Mooncake: up to and including 0.3.13.post1

Published 2026-10-06. Last modified 2026-10-06.