PT-2026-55687 · Federatedai · Fate

·

CVE-2026-14621

·

Published

2026-07-04

·

Updated

2026-07-04

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions FederatedAI FATE versions prior to 2.2.1
Description An issue exists in the OSX Broker component within the QueuePushReqStreamObserver.initEggroll() function. Remote manipulation of the rollSiteSessionId, dstRole, or dstPartyId arguments can lead to the exposure of data elements to an incorrect session. This attack is characterized by high complexity and difficult exploitability.
Recommendations As a temporary workaround, restrict access to the QueuePushReqStreamObserver.initEggroll() function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14621

Affected Products

Fate