CVE-2026-106038 | kvcache-ai Mooncake up to 0.3.13.post1 coro_rpc port Remove/RemoveByRegex/RemoveAll/BatchRemove force missing authentication (EUVD-2026-93401)

SecurityVulns

A vulnerability was found in kvcache-ai Mooncake up to 0.3.13.post1. It has been classified as critical. Affected by this vulnerability is the function Remove/RemoveByRegex/RemoveAll/BatchRemove of the component coro_rpc port. The manipulation of the argument force leads to missing authentication.

This vulnerability is listed as CVE-2026-106038. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More