{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/mooncake-store--0.3.13.post1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mooncake:mooncake_store:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-106040"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Mooncake Store (\u003c= 0.3.13.post1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Mooncake"],"content_html":"\u003cp\u003eMooncake Store versions up to and including 0.3.13.post1 contain a missing authorization vulnerability (CVE-2026-106040). This flaw resides within the coro_rpc master port functionality, which fails to enforce access control checks for sensitive operations. Unauthenticated remote attackers can connect to the exposed master port and invoke the EvictDiskReplica or BatchEvictDiskReplica functions. By successfully executing these functions, an attacker can force the system to evict disk replicas across all tenants. This vulnerability is significant because if a disk replica is the sole remaining copy of an object, invoking these functions results in permanent data loss for those objects. Defenders should restrict network access to the coro_rpc master port to trusted management subnets and upgrade to a patched version once available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to perform unauthorized administrative actions against the storage infrastructure. The primary impact is the potential for permanent data loss across all tenants if an attacker targets objects where the disk replica is the unique surviving copy, leading to widespread service degradation or data destruction.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestrict network access to the coro_rpc master port to only authorized management IPs at the network firewall layer.\u003c/li\u003e\n\u003cli\u003eAudit access logs for unexpected or unauthorized connections originating from non-management subnets targeting the coro_rpc service.\u003c/li\u003e\n\u003cli\u003eMonitor for abnormally high volumes of calls to EvictDiskReplica or BatchEvictDiskReplica functions, as these may indicate malicious activity or system abuse.\u003c/li\u003e\n\u003cli\u003eUpdate Mooncake Store to a version greater than 0.3.13.post1 as soon as a security update is released by the vendor to address the missing authorization logic.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T14:56:28Z","date_published":"2026-10-06T14:56:28Z","id":"https://feed.craftedsignal.io/briefs/2026-10-mooncake-store-missing-auth/","summary":"Mooncake Store versions up to 0.3.13.post1 are vulnerable to a missing authorization flaw in the coro_rpc master port that allows unauthenticated attackers to trigger unauthorized object deletion via replica eviction.","title":"Unauthenticated Disk Replica Eviction in Mooncake Store","url":"https://feed.craftedsignal.io/briefs/2026-10-mooncake-store-missing-auth/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mooncake:mooncake_store:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-106038"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Mooncake Store (\u003c= 0.3.13.post1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Mooncake Store"],"content_html":"\u003cp\u003eMooncake Store versions up to and including 0.3.13.post1 contain a critical missing authentication vulnerability within its coro_rpc communication component. This flaw permits unauthenticated, remote attackers to interact with internal store management functions. By forging specific requests and setting the force flag, an attacker can bypass intended lease validation mechanisms. This allows for unauthorized execution of administrative operations, specifically the Remove, RemoveByRegex, RemoveAll, and BatchRemove commands. Successful exploitation results in the permanent deletion of arbitrary keys or the complete clearing of the data store, leading to immediate cache loss and sustained service failures for applications relying on the Mooncake Store.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability leads to significant data loss and service disruption for environments utilizing Mooncake Store as a caching layer. Attackers can remotely wipe the entire store or selectively target specific keys, which disrupts application operations and forces a loss of cached state. The CVSS 3.1 base score of 8.2 reflects the high impact on availability and the low complexity of the attack, which requires no authentication to execute.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Mooncake Store to a version beyond 0.3.13.post1 immediately upon availability of a patch.\u003c/li\u003e\n\u003cli\u003eImplement network-level segmentation to restrict access to the coro_rpc port to trusted internal management hosts only.\u003c/li\u003e\n\u003cli\u003eMonitor ingress traffic on the coro_rpc port for anomalous patterns or unexpected requests containing deletion-related commands.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T14:56:21Z","date_published":"2026-10-06T14:56:21Z","id":"https://feed.craftedsignal.io/briefs/2026-10-mooncake-auth-bypass/","summary":"Mooncake Store versions through 0.3.13.post1 contain a missing authentication vulnerability in the coro_rpc port, allowing unauthenticated attackers to perform unauthorized deletion operations.","title":"Authentication Bypass in Mooncake Store","url":"https://feed.craftedsignal.io/briefs/2026-10-mooncake-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Mooncake Store (\u003c= 0.3.13.post1)","version":"https://jsonfeed.org/version/1.1"}