CVE-2026-106041: Kvcache-Ai Mooncake
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to inject completed LOCAL_DISK replicas through the NotifyOffloadSuccess RPC. Attackers can mount a local disk segment with a self-chosen client UUID, then attach replicas pointing at attacker-controlled endpoints to serve poisoned disk-tier reads and fake key existence.
Affected products
- Kvcache-Ai Mooncake: up to and including 0.3.13.post1
Published 2026-10-06. Last modified 2026-10-06.