CVE-2026-96762 | kvcache-ai mooncake up to 0.3.12/0.3.13.post1 RPC Path UnmountSegment client_id/segment_id authorization

SecurityVulns

A vulnerability was found in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. It has been classified as critical. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_id/segment_id causes authorization bypass.

This vulnerability is registered as CVE-2026-96762. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More