PT-2026-69961 · Unknown+1 · Feast-Operator+1
CVE-2026-18941
·
Published
2026-08-10
·
Updated
2026-08-11
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Feast (affected versions not specified)
feast-operator (affected versions not specified)
Description
Feast and feast-operator use a default configuration of "no auth", which means no security manager is installed. This allows unauthenticated and unauthorized access to the 'feature-server', 'registry-server', and 'offline-server' endpoints. A remote attacker can exploit this lack of authentication to achieve remote code execution (RCE) by storing a malicious User-Defined Function (UDF) on the 'feature-server', cause a denial of service (DoS) by forcing the re-materialization of all tenant features, or gain unauthorized access to data across different tenants.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
DoS
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Feast
Feast-Operator