CVE-2026-106040 - Mooncake Store through 0.3.13.post1 Missing Authorization via EvictDiskReplica RPC
CVE ID :CVE-2026-106040 Published : Oct. 6, 2026, 2:17 p.m. | 1 hour, 11 minutes ago Description :Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to erase any object's disk replica via EvictDiskReplica and...