Sceawere
Vulnerability Detail
CVE-2026-106037UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Mooncake Authentication Bypass Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 11h ago
- Vendor
- kvcache-ai
- Product
- Mooncake
- Attack Type
- Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the Store REST service, which binds to 0.0.0.0 without authentication on any route. Unauthenticated attackers can call routes such as /api/get, /api/put, /api/remove_all and /api/mount to read cached KV data with user prompts, inject or delete objects, and mount attacker-described segments.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-06T14:17:42.257Z",
"pubdate": "2026-10-06T14:17:42.257Z",
"executiveSummary": "Mooncake versions up to 0.3.13.post1 are susceptible to a critical missing authentication vulnerability within the Store REST service.\nThe vulnerability originates from the service binding to 0.0.0.0 without implementing any form of access control or authentication mechanisms across its API routes.\nThis flaw allows unauthenticated, remote attackers to interact directly with the KV (Key-Value) store, leading to unauthorized data exfiltration, modification, and service manipulation.\nThe risk is severe, as it permits attackers to manipulate cached user prompts, perform unauthorized object injection, delete sensitive data, and mount attacker-controlled segments, potentially leading to full compromise of the cached data and integrity of the application flow.\nNo authentication or elevated privileges are required for exploitation, as the API surfaces are exposed globally, making it a highly accessible target for any adversary with network connectivity to the affected service.",
"technicalDetails": "The vulnerability resides in the Store REST service of Mooncake, which fails to enforce authentication checks for any of its exposed API routes. By binding the service to the wildcard interface 0.0.0.0, the application makes its internal REST endpoints globally accessible over the network without requiring valid credentials.\nThe identified vulnerable endpoints include, but are not limited to, /api/get, /api/put, /api/remove_all, and /api/mount. These functions serve as the primary interface for managing cached KV data. Because the application logic lacks a middleware or authorization layer to verify the identity of the requester, any packet directed at these paths is processed as a legitimate administrative action.\nThe exploitation flow begins with the discovery of the open REST port. An attacker can craft HTTP requests targeting these specific routes. For instance, sending an unauthenticated GET request to /api/get allows an attacker to dump the contents of the KV store, resulting in the unauthorized disclosure of sensitive user prompts. An attacker can subsequently use the /api/put route to inject arbitrary key-value pairs into the cache, potentially poisoning the data used by the application or altering its control flow.\nFurthermore, the /api/remove_all route grants the attacker the ability to perform a destructive operation, purging the entire cache state and causing a denial-of-service condition for the application's caching functionality. The most critical aspect of the vulnerability involves the /api/mount route, which allows an attacker to mount attacker-described segments. This capability can be leveraged to redirect data lookups to malicious, attacker-controlled storage segments, facilitating sophisticated data exfiltration or the persistent injection of malicious payloads into the system's runtime environment.\nBecause the service operates on 0.0.0.0, any entity with network-layer access to the host can interact with the API, bypassing all perimeter defenses if the host is not behind an additional robust firewall. The impact spans from full data confidentiality loss to total integrity compromise of the stored cached objects, providing the attacker with significant control over the data processed by the Mooncake instance."
}