<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Mooncake Store (&lt;= 0.3.13.post1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/mooncake-store--0.3.13.post1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 14:56:28 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/mooncake-store--0.3.13.post1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Disk Replica Eviction in Mooncake Store</title><link>https://feed.craftedsignal.io/briefs/2026-10-mooncake-store-missing-auth/</link><pubDate>Tue, 06 Oct 2026 14:56:28 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-mooncake-store-missing-auth/</guid><description>Mooncake Store versions up to 0.3.13.post1 are vulnerable to a missing authorization flaw in the coro_rpc master port that allows unauthenticated attackers to trigger unauthorized object deletion via replica eviction.</description><content:encoded><![CDATA[<p>Mooncake Store versions up to and including 0.3.13.post1 contain a missing authorization vulnerability (CVE-2026-106040). This flaw resides within the coro_rpc master port functionality, which fails to enforce access control checks for sensitive operations. Unauthenticated remote attackers can connect to the exposed master port and invoke the EvictDiskReplica or BatchEvictDiskReplica functions. By successfully executing these functions, an attacker can force the system to evict disk replicas across all tenants. This vulnerability is significant because if a disk replica is the sole remaining copy of an object, invoking these functions results in permanent data loss for those objects. Defenders should restrict network access to the coro_rpc master port to trusted management subnets and upgrade to a patched version once available.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to perform unauthorized administrative actions against the storage infrastructure. The primary impact is the potential for permanent data loss across all tenants if an attacker targets objects where the disk replica is the unique surviving copy, leading to widespread service degradation or data destruction.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Restrict network access to the coro_rpc master port to only authorized management IPs at the network firewall layer.</li>
<li>Audit access logs for unexpected or unauthorized connections originating from non-management subnets targeting the coro_rpc service.</li>
<li>Monitor for abnormally high volumes of calls to EvictDiskReplica or BatchEvictDiskReplica functions, as these may indicate malicious activity or system abuse.</li>
<li>Update Mooncake Store to a version greater than 0.3.13.post1 as soon as a security update is released by the vendor to address the missing authorization logic.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item><item><title>Authentication Bypass in Mooncake Store</title><link>https://feed.craftedsignal.io/briefs/2026-10-mooncake-auth-bypass/</link><pubDate>Tue, 06 Oct 2026 14:56:21 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-mooncake-auth-bypass/</guid><description>Mooncake Store versions through 0.3.13.post1 contain a missing authentication vulnerability in the coro_rpc port, allowing unauthenticated attackers to perform unauthorized deletion operations.</description><content:encoded><![CDATA[<p>Mooncake Store versions up to and including 0.3.13.post1 contain a critical missing authentication vulnerability within its coro_rpc communication component. This flaw permits unauthenticated, remote attackers to interact with internal store management functions. By forging specific requests and setting the force flag, an attacker can bypass intended lease validation mechanisms. This allows for unauthorized execution of administrative operations, specifically the Remove, RemoveByRegex, RemoveAll, and BatchRemove commands. Successful exploitation results in the permanent deletion of arbitrary keys or the complete clearing of the data store, leading to immediate cache loss and sustained service failures for applications relying on the Mooncake Store.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability leads to significant data loss and service disruption for environments utilizing Mooncake Store as a caching layer. Attackers can remotely wipe the entire store or selectively target specific keys, which disrupts application operations and forces a loss of cached state. The CVSS 3.1 base score of 8.2 reflects the high impact on availability and the low complexity of the attack, which requires no authentication to execute.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and infrastructure teams:</p>
<ul>
<li>Update Mooncake Store to a version beyond 0.3.13.post1 immediately upon availability of a patch.</li>
<li>Implement network-level segmentation to restrict access to the coro_rpc port to trusted internal management hosts only.</li>
<li>Monitor ingress traffic on the coro_rpc port for anomalous patterns or unexpected requests containing deletion-related commands.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>