← Back to CVE List
CVE-2026-107206NVD
Vulnerability Summary
LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attackers to access management endpoints listening on all interfaces by default. Attackers can read environment credentials via GET /env and configuration via GET /config, clear caches, delete cache objects, and modify tenant quotas to evict other tenants' cached data.
CVSS v4.0 Base Metrics — Score 8.8 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)Low
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 9.4 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityLow
AvailabilityHigh
Affected & Patched Versions
- LMCache LMCache <= 0.5.5
- LMCache LMCache 0.5.5
External References
- https://github.com/LMCache/LMCache/issues/5511
- https://github.com/LMCache/LMCache
- https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/multiprocess/config.py#L206
- https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/internal_api_server/common/env_api.py#L13
- https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/multiprocess/http_apis/quota_api.py#L138-L155
- https://www.vulncheck.com/advisories/lmcache-through-0.5.5-missing-authentication-in-mp-http-server-management-api