CVE-2026-96762: kvcache-ai mooncake RPC Path UnmountSegment authorization
A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument clientid/segmentid causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker can exploit it without privileges or user interaction. The affected RPC Path Handler's UnmountSegment function can be manipulated through the client_id and segment_id arguments to bypass authorization.
Which releases are affected?
The issue affects kvcache-ai mooncake up to version 0.3.12 and 0.3.13.post1. No fixed version is identified in the provided information.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used by attackers.