Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to inject completed LOCAL_DISK replicas through the NotifyOffloadSuccess RPC. Attackers can mount a local disk segment with a self-chosen client UUID, then attach replicas pointing at attacker-controlled endpoints to serve poisoned disk-tier reads and fake key existence.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 Oct 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to inject completed LOCAL_DISK replicas through the NotifyOffloadSuccess RPC. Attackers can mount a local disk segment with a self-chosen client UUID, then attach replicas pointing at attacker-controlled endpoints to serve poisoned disk-tier reads and fake key existence. | |
| Title | Mooncake Store through 0.3.13.post1 Missing Authorization via NotifyOffloadSuccess RPC | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-06T17:16:25.232Z
Reserved: 2026-10-06T13:53:18.545Z
Link: CVE-2026-106041
No data.
Status : Deferred
Published: 2026-10-06T14:17:43.983
Modified: 2026-10-06T15:25:00.650
Link: CVE-2026-106041
No data.
OpenCVE Enrichment
No data.
Weaknesses