Critical severity9.4NVD Advisory· Published Oct 7, 2026· Updated Oct 7, 2026
CVE-2026-107206
CVE-2026-107206
Description
LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attackers to access management endpoints listening on all interfaces by default. Attackers can read environment credentials via GET /env and configuration via GET /config, clear caches, delete cache objects, and modify tenant quotas to evict other tenants' cached data.
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/internal_api_server/common/env_api.pynvd
- github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/multiprocess/config.pynvd
- github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/multiprocess/http_apis/quota_api.pynvd
- github.com/LMCache/LMCache/issues/5511nvd
- www.vulncheck.com/advisories/lmcache-through-0.5.5-missing-authentication-in-mp-http-server-management-apinvd
News mentions
0No linked articles in our index yet.