CVE-2026-106039 | kvcache-ai Mooncake up to 0.3.13.post1 coro_rpc port UUID authorization (EUVD-2026-93402)
A vulnerability was found in kvcache-ai Mooncake up to 0.3.13.post1. It has been declared as very critical. Affected by this issue is the function CreateCopyTask/CreateMoveTask/FetchTasks/MarkTaskToComplete/QueryTask of the component coro_rpc port. The manipulation of the argument UUID results in missing authorization.
This vulnerability is cataloged as CVE-2026-106039. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More