Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to erase any object's disk replica via EvictDiskReplica and BatchEvictDiskReplica. Attackers reaching the coro_rpc master port can evict DISK replicas across all tenants, deleting objects whose only remaining replica is on disk. | |
| Title | Mooncake Store through 0.3.13.post1 Missing Authorization via EvictDiskReplica RPC | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-06T14:03:17.053Z
Reserved: 2026-10-06T13:53:18.034Z
Link: CVE-2026-106040
No data.
Status : Deferred
Published: 2026-10-06T14:17:43.833
Modified: 2026-10-06T15:25:00.650
Link: CVE-2026-106040
No data.
OpenCVE Enrichment
No data.
-
CWE-862
Missing Authorization