high · CVSS v3 7.3 · CVSS v4 6.9 · EPSS 0.00292
CVE-2026-96762
kvcache-ai mooncake up to 0.3.12/0.3.13.post1 has an authorization bypass in the UnmountSegment RPC Path Handler. Attackers can manipulate c
Overview
kvcache-ai mooncake up to 0.3.12/0.3.13.post1 has an authorization bypass in the UnmountSegment RPC Path Handler. Attackers can manipulate client_id/segment_id to gain unauthorized access. Remote exploitation is possible.
Description
A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_id/segment_id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Impact
Confidentiality: unauthorized data access. Integrity: unauthorized modification of cache segments. Availability: potential denial of service if segments are improperly unmounted. Impacted parties: administrators and users of kvcache-ai mooncake deployments.
Remediation
Apply the vendor patch that fixes UnmountSegment authorization checks. If patch unavailable, restrict RPC endpoint access to trusted IPs or enforce strict client_id validation. Disable or limit UnmountSegment functionality if not needed. Monitor logs for unauthorized client_id/segment_id patterns.
Risk context
High severity (CVSS 7.3) with low EPSS (0.00292) indicates moderate likelihood but high impact. Immediate patching is recommended to prevent potential remote exploitation.
Affected products
- kvcache-ai mooncake
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 7.3
- CVSS v4
- 6.9
- EPSS
- 0.00292