Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to inject completed LOCAL_DISK replicas through the NotifyOffloadSuccess RPC. Attackers can mount a local disk segment with a self-chosen client UUID, then attach replicas pointing at attacker-controlled endpoints to serve poisoned disk-tier reads and fake key existence. | |
| Title | Mooncake Store through 0.3.13.post1 Missing Authorization via NotifyOffloadSuccess RPC | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-06T14:03:17.708Z
Reserved: 2026-10-06T13:53:18.545Z
Link: CVE-2026-106041
No data.
Status : Deferred
Published: 2026-10-06T14:17:43.983
Modified: 2026-10-06T15:25:00.650
Link: CVE-2026-106041
No data.
OpenCVE Enrichment
No data.