<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:kvcache_ai:mooncake:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3akvcache_aimooncake/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 24 Sep 2026 00:45:44 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3akvcache_aimooncake/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in kvcache-ai Mooncake RPC Path Handler</title><link>https://feed.craftedsignal.io/briefs/2026-09-mooncake-auth-bypass/</link><pubDate>Thu, 24 Sep 2026 00:45:44 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-mooncake-auth-bypass/</guid><description>An authorization bypass vulnerability in the UnmountSegment function of the kvcache-ai mooncake RPC Path Handler allows unauthenticated remote attackers to perform unauthorized operations by manipulating client_id or segment_id arguments.</description><content:encoded><![CDATA[<p>CVE-2026-96762 identifies an authorization bypass vulnerability affecting kvcache-ai mooncake versions up to and including 0.3.13.post1. The flaw exists within the UnmountSegment function of the RPC Path Handler component. Due to insufficient validation of input arguments, an attacker can manipulate the client_id or segment_id parameters during an RPC request to circumvent security controls. This vulnerability allows for remote exploitation, potentially enabling unauthorized access to or manipulation of cached segments. A proof-of-concept exploit has been publicly disclosed, increasing the risk of active exploitation. The vendor has not provided a response or a security patch as of the time of disclosure, leaving implementations of mooncake in the affected versions currently vulnerable to unauthorized administrative actions.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthorized remote actors to interact with the RPC Path Handler in unintended ways, potentially leading to unauthorized data modification or segment unmounting. This poses a significant risk to the integrity and availability of services relying on mooncake for caching. As public exploits are available, the probability of targeting by opportunistic attackers is elevated.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor network traffic directed at the mooncake RPC endpoints for anomalous requests containing modified client_id or segment_id parameters.</li>
<li>Implement strict network segmentation to restrict access to the RPC interface to trusted internal systems only.</li>
<li>Given the lack of a vendor patch, evaluate the necessity of the mooncake service and consider isolating or disabling the service if it cannot be adequately protected behind authentication or network controls.</li>
<li>Audit access logs for the RPC Path Handler to identify any unusual UnmountSegment calls that deviate from standard service behavior.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>vulnerability</category><category>remote-access</category><category>rpc</category></item></channel></rss>