External risk intelligence

Mooncake REST Service Missing Authentication Leading to Data Access and Manipulation.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-106037

The vulnerability exists in a REST service that explicitly binds to 0.0.0.0 and exposes API endpoints for data manipulation without any authentication. Because it is designed to operate as a network-accessible service and listens on all interfaces by default, it is highly likely to be reachable if deployed in an internet-facing configuration.

Missing Authentication

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical security vulnerability found in the Mooncake software's Store REST service. The service improperly handles authentication, allowing unauthenticated access to read, inject, or delete cached data and objects. This could enable unauthorized manipulation of stored information.

  • Unauthenticated access to store data and functions.
  • Critical exposure if Mooncake is internet-facing.
  • Confirm relevance and exposure for Mooncake deployments.

Attack Path

How an attacker could exploit the issue

An attacker can reach the vulnerable Mooncake Store REST service over the network because it binds to all available network interfaces without requiring any authentication. By sending specially crafted requests to exposed API routes, an attacker can interact with cached data, including reading, injecting, or deleting objects, and mounting custom segments. This allows for unauthorized access and manipulation of sensitive information and system components.

  • Accessible over the network.
  • Unauthenticated API endpoints.
  • Read, modify, or delete data.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to access, modify, or delete cached data, inject malicious data, or mount custom segments within the Mooncake Store REST service. This is possible because the service binds to all network interfaces and does not require authentication on its API routes.

  • Cached KV data and stored objects at risk.
  • Attackers can directly call exposed API routes.
  • Unauthorized access and data manipulation.

Operational Fix

Recommended remediation, mitigation, and detection steps

The technical owner for this critical vulnerability likely resides within the team managing the Mooncake application or the platform team responsible for its deployment. The first practical step is to discover all instances of Mooncake, assess their network exposure and business criticality, and identify the accountable owner for each instance to prioritize remediation.

  • Identify Mooncake instances and owners.
  • Verify network exposure and criticality.
  • Plan and coordinate remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Mooncake?

Mooncake is an open-source software project designed for managing key-value (KV) data caching. It provides a specialized storage service to help optimize data retrieval and object handling within technical workflows. By using a REST service architecture, it allows different parts of a system to quickly interact with cached information, though this specific implementation handles sensitive data operations.

What does CWE-306 mean for CVE-2026-106037?

CWE-306 refers to a 'Missing Authentication for Critical Function' weakness. In the context of CVE-2026-106037, this means the Mooncake Store REST service lacks any identity verification checks. Because the software does not ask for credentials or tokens, it treats any incoming network request as trusted, permitting anyone to execute sensitive commands like modifying or deleting cached data.

How do attackers trigger this vulnerability?

An attacker triggers the bug by sending direct HTTP requests to the Mooncake Store REST service API. The service is configured to bind to 0.0.0.0, meaning it listens on all available network interfaces, including those reachable from outside a local machine. Simply visiting or sending data to routes like /api/put or /api/remove_all allows unauthorized control; authentication is not a required precondition for these interactions.

Is my instance of Mooncake at risk?

If you run Mooncake, your risk depends on network visibility. Halo Surface Signal notes that because the service binds to all network interfaces (0.0.0.0) by default, it is highly likely to be reachable if your deployment is internet-facing. If the service is accessible outside of a secure, internal, or isolated network, it is exposed to anyone capable of reaching the service via the network.

What steps should I take if I use Mooncake?

Start by identifying all deployed instances of Mooncake within your environment to determine which ones are running the affected versions. Evaluate whether these instances are connected to untrusted networks or the public internet. Coordinate with your platform or security teams to isolate the service, restrict network access, and prepare for updates once the software maintainers provide a resolution.

References