---
id: CVE-2026-96762
title: >-
  A vulnerability was determined in kvcache-ai mooncake up to
  0.3.12/0.3.13.post1
summary: >-
  A vulnerability was determined in kvcache-ai mooncake up to
  0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component
  RPC Path Handler. This manipulation of the argument client_id/segment_id
  causes authorization bypa…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-285
  - CWE-639
vendor: kvcache-ai
product: mooncake
affected:
  - mooncake 0.3.0
  - mooncake 0.3.1
  - mooncake 0.3.2
  - mooncake 0.3.3
  - mooncake 0.3.4
  - mooncake 0.3.5
  - mooncake 0.3.6
  - mooncake 0.3.7
  - mooncake 0.3.8
  - mooncake 0.3.9
  - mooncake 0.3.10
  - mooncake 0.3.11
  - mooncake 0.3.12
  - mooncake 0.3.13.post1
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96762'
references:
  - url: 'https://gist.github.com/yyymk/76d099537af0e661dd01eacc82b9a7ea'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-96762'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/904600'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409016'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409016/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
epss: 0.00292
epssPercentile: 0.19427
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-24T13:17:42.616673Z'
ingestedAt: '2026-09-24T00:35:28.613Z'
---

## Overview

A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_id/segment_id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
