CVE-2026-107206
Received Received - Intake

LMCache Missing Authentication in Multiprocess Mode

Vulnerability report for CVE-2026-107206, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: VulnCheck

Description

LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attackers to access management endpoints listening on all interfaces by default. Attackers can read environment credentials via GET /env and configuration via GET /config, clear caches, delete cache objects, and modify tenant quotas to evict other tenants' cached data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
LMCache LMCache 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

LMCache through version 0.5.5 has a missing authentication vulnerability in its multiprocess mode HTTP server. This flaw allows remote attackers to access management endpoints without authentication. Attackers can read environment credentials via GET /env, view configuration via GET /config, clear caches, delete cache objects, and modify tenant quotas to evict other tenants' cached data.

Detection Guidance
  • Check if LMCache is running on port 8080 by default. Use commands like 'netstat -tulnp | grep 8080' or 'ss -tulnp | grep 8080' to verify if the HTTP server is listening on all interfaces (0.0.0.0:8080).
  • Send HTTP GET requests to endpoints like /env, /config, /status, /quota, /cache/clear, and /cache/objects to check for unauthenticated access. Example: 'curl http://<target-ip>:8080/env' or 'curl http://<target-ip>:8080/config'.
  • Inspect network traffic for unusual activity targeting port 8080 or other HTTP endpoints associated with LMCache management APIs.
Impact Analysis

This vulnerability allows attackers to read sensitive data like API tokens and service credentials, delete or modify cached data, and disrupt services by clearing caches or evicting other tenants' data. It can lead to data breaches, service disruptions, and unauthorized access to system configurations.

Compliance Impact

This vulnerability can lead to non-compliance with GDPR and HIPAA by exposing sensitive data such as environment credentials and configuration details. Unauthorized access to cached data may violate data protection requirements, leading to legal and regulatory penalties.

Mitigation Strategies

Immediately restrict network access to the LMCache HTTP server by binding it to localhost (127.0.0.1) instead of all interfaces (0.0.0.0). Update firewall rules to block external access to port 8080 or the LMCache management endpoints.

Disable or remove the LMCache multiprocess HTTP server if it is not required for operations. Monitor for any unauthorized cache modifications or data exfiltration attempts.

Apply network segmentation to isolate the LMCache server from untrusted networks. Review and remove sensitive data from environment variables and configurations exposed by the /env and /config endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107206. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart