---
id: CVE-2026-96763
title: >-
  A security flaw has been discovered in kvcache-ai mooncake up to
  0.3.12/0.3.13.post1/0.3.14-rc1
summary: >-
  A security flaw has been discovered in kvcache-ai mooncake up to
  0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the function
  ScopedSegmentAccess::MountSegment of the file segment.cpp of the component
  MountSegment Request Processing. …
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'
cwe:
  - CWE-266
  - CWE-284
vendor: kvcache-ai
product: mooncake
affected:
  - mooncake 0.3.0
  - mooncake 0.3.1
  - mooncake 0.3.2
  - mooncake 0.3.3
  - mooncake 0.3.4
  - mooncake 0.3.5
  - mooncake 0.3.6
  - mooncake 0.3.7
  - mooncake 0.3.8
  - mooncake 0.3.9
  - mooncake 0.3.10
  - mooncake 0.3.11
  - mooncake 0.3.12
  - mooncake 0.3.13.post1
  - mooncake 0.3.14-rc1
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:40:36.103'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96763'
references:
  - url: 'https://gist.github.com/yyymk/fea24846dc31042cb472d7bd496a8438'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-96763'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/904605'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409018'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409018/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-24T00:35:28.615Z'
epss: 0.00247
epssPercentile: 0.14207
---

## Overview

A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the function ScopedSegmentAccess::MountSegment of the file segment.cpp of the component MountSegment Request Processing. Performing a manipulation results in improper access controls. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
