Mooncake · Mooncake · CVE-2026-96763
**Name of the Vulnerable Software and Affected Versions**
kvcache-ai mooncake versions 0.3.12 through 0.3.14-rc1
**Description**
Improper access controls exist within the MountSegment Request Processing component, specifically affecting the `ScopedSegmentAccess::MountSegment()` function in the `segment.cpp` file. This flaw allows a remote attacker to perform manipulations that bypass intended access restrictions.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, restrict access to the `ScopedSegmentAccess::MountSegment()` function.