CVE-2026-106040: Mooncake Store through 0.3.13.post1 Missing Authorization via EvictDiskReplica RPC
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to erase any object's disk replica via EvictDiskReplica and BatchEvictDiskReplica. Attackers reaching the cororpc master port can evict DISK replicas across all tenants, deleting objects whose only remaining replica is on disk.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Mooncake Store master instances through 0.3.13.post1 are exposed if an attacker can reach the coro_rpc master port. The affected RPCs can target disk replicas across all tenants.
Does an attacker need credentials or user interaction?
No. Exploitation is unauthenticated and requires neither privileges nor user interaction, provided the attacker can reach the master port.
What is the practical impact of a successful attack?
An attacker can evict an object's DISK replica using EvictDiskReplica or BatchEvictDiskReplica. Objects whose only remaining replica is on disk can be deleted.