Skip to content
Threat Feed
high advisory

Unauthenticated Disk Replica Eviction in Mooncake Store

Mooncake Store versions up to 0.3.13.post1 are vulnerable to a missing authorization flaw in the coro_rpc master port that allows unauthenticated attackers to trigger unauthorized object deletion via replica eviction.

CVE search metadata

CVE search record: CVE-2026-106040. Severity: high. CVSS: 8.2. KEV: no. Product: Mooncake Store (<= 0.3.13.post1). Brief: Unauthenticated Disk Replica Eviction in Mooncake Store. Brief link: https://feed.craftedsignal.io/briefs/2026-10-mooncake-store-missing-auth/

Mooncake Store versions up to and including 0.3.13.post1 contain a missing authorization vulnerability (CVE-2026-106040). This flaw resides within the coro_rpc master port functionality, which fails to enforce access control checks for sensitive operations. Unauthenticated remote attackers can connect to the exposed master port and invoke the EvictDiskReplica or BatchEvictDiskReplica functions. By successfully executing these functions, an attacker can force the system to evict disk replicas across all tenants. This vulnerability is significant because if a disk replica is the sole remaining copy of an object, invoking these functions results in permanent data loss for those objects. Defenders should restrict network access to the coro_rpc master port to trusted management subnets and upgrade to a patched version once available.

Impact

Successful exploitation allows unauthenticated attackers to perform unauthorized administrative actions against the storage infrastructure. The primary impact is the potential for permanent data loss across all tenants if an attacker targets objects where the disk replica is the unique surviving copy, leading to widespread service degradation or data destruction.

Recommendation

  • Restrict network access to the coro_rpc master port to only authorized management IPs at the network firewall layer.
  • Audit access logs for unexpected or unauthorized connections originating from non-management subnets targeting the coro_rpc service.
  • Monitor for abnormally high volumes of calls to EvictDiskReplica or BatchEvictDiskReplica functions, as these may indicate malicious activity or system abuse.
  • Update Mooncake Store to a version greater than 0.3.13.post1 as soon as a security update is released by the vendor to address the missing authorization logic.

Immediate actions

Block unauthorized network access to the coro_rpc master port

IT Operations 24h

Mitigations

Restrict coro_rpc master port access via network ACLs

immediate IT Operations

CVE-2026-106040