Mooncake Store 0.3.13.post1 及之前版本存在一个缺失身份验证漏洞。攻击者可通过 coro_rpc 端口对未认证请求执行操作,从而创建、窃取和伪造完成复制任务。攻击者可以调用 CreateCopyTask、CreateMoveTask、FetchTasks 和 MarkTaskToComplete,并利用通过 QueryTask 泄露的受害者客户端 UUID,劫持任务队列,并记录从未实际发生的复制操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kvcache-ai | Mooncake | 0 ~ 0.3.13.post1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106037 | 9.8 CRITICAL | Mooncake through 0.3.13.post1 Missing Authentication in Store REST Service |
| CVE-2026-106040 | 8.2 HIGH | Mooncake Store through 0.3.13.post1 Missing Authorization via EvictDiskReplica RPC |
| CVE-2026-106038 | 8.2 HIGH | Mooncake Store through 0.3.13.post1 Unauthenticated Object Deletion via Remove RPCs |
| CVE-2026-106041 | 6.5 MEDIUM | Mooncake Store through 0.3.13.post1 Missing Authorization via NotifyOffloadSuccess RPC |
No comments yet