medium · CVSS v3 5.4 · CVSS v4 5.3 · EPSS 0.00247
CVE-2026-96763
A flaw in kvcache-ai mooncake’s ScopedSegmentAccess::MountSegment function allows remote attackers to bypass access controls. The vulnerabil
Overview
A flaw in kvcache-ai mooncake’s ScopedSegmentAccess::MountSegment function allows remote attackers to bypass access controls. The vulnerability exists in versions up to 0.3.12, 0.3.13.post1, and 0.3.14-rc1. It can lead to unauthorized data access or modification.
Description
A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the function ScopedSegmentAccess::MountSegment of the file segment.cpp of the component MountSegment Request Processing. Performing a manipulation results in improper access controls. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Impact
The flaw compromises confidentiality, integrity, and potentially availability of data stored in the affected segments. Attackers can read or alter protected data without proper authorization. Defenders using these versions are at risk of data leakage or tampering. The impact is limited to systems that expose the vulnerable component to external networks.
Remediation
Apply the vendor’s patch or upgrade to a version newer than 0.3.14-rc1 (e.g., 0.3.15 or later). If an upgrade is not immediately possible, restrict network access to the MountSegment API using firewall rules or VPNs, and disable the feature if it is not required. Monitor logs for anomalous MountSegment requests and enforce strict authentication and authorization checks.
Risk context
The CVSS v3 score is 5.4 (medium) and the EPSS score is 0.00247, indicating a low probability of exploitation but a moderate impact if successful. Defenders should treat this as a medium‑severity issue and prioritize patching or mitigation accordingly.
Affected products
- kvcache-ai mooncake 0.3.12
- kvcache-ai mooncake 0.3.13.post1
- kvcache-ai mooncake 0.3.14-rc1
Scores
- Severity
- medium
- CVSS v2
- 6.4
- CVSS v3
- 5.4
- CVSS v4
- 5.3
- EPSS
- 0.00247