Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to create, steal, and falsely complete replication tasks via the coro_rpc port. Attackers can invoke CreateCopyTask, CreateMoveTask, FetchTasks, and MarkTaskToComplete with victim client UUIDs disclosed by QueryTask to hijack task queues and record replication that never occurred. | |
| Title | Mooncake Store through 0.3.13.post1 Missing Authorization in Replication Task RPC | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-06T15:37:52.711Z
Reserved: 2026-10-06T13:53:17.708Z
Link: CVE-2026-106039
No data.
Status : Deferred
Published: 2026-10-06T14:17:43.660
Modified: 2026-10-06T15:25:00.650
Link: CVE-2026-106039
No data.
OpenCVE Enrichment
No data.