CVE-2026-106038 - Mooncake Store through 0.3.13.post1 Unauthenticated Object Deletion via Remove RPCs
CVE ID :CVE-2026-106038 Published : Oct. 6, 2026, 2:17 p.m. | 1 hour, 11 minutes ago Description :Mooncake Store master through 0.3.13.post1 contains a missing authentication vulnerability that allows unauthenticated attackers to force-delete any object via Remove, RemoveByRegex, RemoveAll...