Description
Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the Store REST service, which binds to 0.0.0.0 without authentication on any route. Unauthenticated attackers can call routes such as /api/get, /api/put, /api/remove_all and /api/mount to read cached KV data with user prompts, inject or delete objects, and mount attacker-described segments.
Published: 2026-10-06
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Unauthenticated remote access to the Store REST service that allows attackers to read, write, delete data and mount segments
Action: Immediate Patch
AI Analysis

Impact

Mooncake version 0.3.13.post1 and earlier contain a missing authentication defect in the Store REST service. The service listens on all interfaces (0.0.0.0) and does not require credentials, permitting any network user to call endpoints such as /api/get, /api/put, /api/remove_all and /api/mount. These endpoints expose cached key-value data, allow arbitrary object injection or deletion, and enable attackers to mount segments defined by the attacker, effectively letting them manipulate the storage state.

Affected Systems

The vulnerability affects kvcache-ai’s Mooncake product for versions up to and including 0.3.13.post1. Users running any of these releases are susceptible to unprotected access to the Store REST API.

Risk and Exploitability

The CVSS score of 9.3 signals a high severity issue with full confidentiality, integrity, and availability impact. The vulnerability is accessible from any host that can reach the 0.0.0.0 address, making it a remote exploit with no authentication or privilege escalation prerequisites. EPSS is not available, but the absence from the KEV catalog does not diminish the risk, especially given the potentially broad impact. Attacker can fully control the storage service, compromising data integrity and application state.

Generated by OpenCVE AI on October 6, 2026 at 18:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a patched version of Mooncake that enforces authentication on the Store REST service.
  • If an upgrade is not immediately possible, restrict network exposure of the Store service by blocking external access to the listening port or by binding the service to localhost only.
  • As an additional safeguard, implement an authentication layer or reverse proxy in front of the service to require credentials before any request reaches the Store REST endpoints.

Generated by OpenCVE AI on October 6, 2026 at 18:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the Store REST service, which binds to 0.0.0.0 without authentication on any route. Unauthenticated attackers can call routes such as /api/get, /api/put, /api/remove_all and /api/mount to read cached KV data with user prompts, inject or delete objects, and mount attacker-described segments.
Title Mooncake through 0.3.13.post1 Missing Authentication in Store REST Service
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-06T16:10:40.481Z

Reserved: 2026-10-06T13:53:09.401Z

Link: CVE-2026-106037

cve-icon Vulnrichment

Updated: 2026-10-06T16:10:15.282Z

cve-icon NVD

Status : Deferred

Published: 2026-10-06T14:17:42.257

Modified: 2026-10-06T17:17:23.840

Link: CVE-2026-106037

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:30:05Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function