Federatedai · Fate · CVE-2026-14621
**Name of the Vulnerable Software and Affected Versions**
FederatedAI FATE versions prior to 2.2.1
**Description**
An issue exists in the OSX Broker component within the `QueuePushReqStreamObserver.initEggroll()` function. Remote manipulation of the `rollSiteSessionId`, `dstRole`, or `dstPartyId` arguments can lead to the exposure of data elements to an incorrect session. This attack is characterized by high complexity and difficult exploitability.
**Recommendations**
As a temporary workaround, restrict access to the `QueuePushReqStreamObserver.initEggroll()` function to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.