Security Flaw in Feast and Feast-Operator from Red Hat
CVE-2026-18941

7.7HIGH

What is CVE-2026-18941?

A security flaw in the Feast SDK and feast-operator arises from a default configuration that lacks authentication, allowing unauthorized access to key server endpoints. This vulnerability enables attackers to potentially execute remote code via malicious User-Defined Functions (UDFs) and can lead to denial of service (DoS) by forcing unnecessary re-materialization of features across tenants. Moreover, it poses a risk of unauthorized access to cross-tenant data, which can drastically compromise data integrity and privacy.

Affected Version(s)

Red Hat OpenShift AI 2.25 1786110051

Red Hat OpenShift AI 3.3 1786110033

Red Hat OpenShift AI 3.4 1786107278

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.