CVE-2026-106039 UNKNOWN

CVE-2026-106039

Published: 2026-10-06

Description

Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to create, steal, and falsely complete replication tasks via the coro_rpc port. Attackers can invoke CreateCopyTask, CreateMoveTask, FetchTasks, and MarkTaskToComplete with victim client UUIDs disclosed by QueryTask to hijack task queues and record replication that never occurred.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…