Sceawere
Vulnerability Detail
CVE-2026-103765UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Mooncake Metadata Server Unauthorized Access
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.4
- Creation Date
- 23h ago
- Vendor
- kvcache-ai
- Product
- Mooncake
- Attack Type
- Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server memory.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.4",
"pubDate": "2026-10-02T00:16:59.663Z",
"pubdate": "2026-10-02T00:16:59.663Z",
"executiveSummary": "Mooncake versions up to 0.3.13.post1 are susceptible to an authentication bypass vulnerability within the HTTP metadata server /metadata handler.\nThis flaw enables unauthenticated remote attackers to perform unauthorized CRUD (Create, Read, Update, Delete) operations on sensitive transfer engine metadata keys.\nThe vulnerability poses a severe risk to data integrity and system availability. By manipulating metadata, an attacker can hijack KV cache transfers by redirecting data streams to malicious, attacker-controlled endpoints.\nFurthermore, the ability to delete or overwrite keys allows for resource exhaustion, potentially leading to server-side denial-of-service conditions.\nThere are no requirements for valid credentials, meaning the metadata interface is exposed to any actor with network connectivity to the service.\nThis represents a significant security oversight in the handling of internal metadata state, necessitating immediate attention to restrict access to administrative interfaces.",
"technicalDetails": "The root cause of this vulnerability is a missing authentication check in the HTTP metadata server's /metadata handler in Mooncake through 0.3.13.post1. The application fails to implement identity verification or session validation for requests directed at this endpoint.\nThe vulnerable component is the metadata management service, which is responsible for tracking transfer engine states and segment descriptors. Because the endpoint lacks access control, any network-adjacent attacker can interact with the server's internal state management API.\nAttack flow: 1. An attacker identifies the exposed /metadata handler via network discovery. 2. The attacker crafts arbitrary HTTP requests to interact with the metadata store. 3. By performing a PUT or POST request, the attacker modifies existing keys or injects new ones. 4. Specifically, an attacker can manipulate segment descriptors such as 'tcp_data_port'. 5. By re-configuring 'rpc_meta' entries, the attacker effectively modifies the routing logic for KV cache transfers.\nThe payload behavior involves overwriting legitimate metadata with malicious values to redirect data traffic to an attacker-controlled listener. This allows the attacker to intercept sensitive KV cache contents as they are transferred across the network.\nAlternatively, an attacker can perform a series of DELETE requests or inject massive quantities of dummy data, leading to memory exhaustion within the server environment. This effectively crashes the transfer engine or degrades system performance to the point of unavailability.\nThe lack of authentication means that no privilege escalation is required to achieve full control over the metadata state. The exposure is total for any network path that can route traffic to the metadata server's port.\nPost-exploitation impact includes the full compromise of data confidentiality during cache transfers, man-in-the-middle capability, and the potential for persistent denial-of-service attacks against the transfer orchestration layer."
}