Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-106041

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Oct 06, 2026
Vendor unknown

Description

Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to inject completed LOCAL_DISK replicas through the NotifyOffloadSuccess RPC. Attackers can mount a local disk segment with a self-chosen client UUID, then attach replicas pointing at attacker-controlled endpoints to serve poisoned disk-tier reads and fake key existence.

References