Code Injection Vulnerability in Feast Operator by Red Hat
CVE-2026-18942
5.5MEDIUM
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 10 August 2026
What is CVE-2026-18942?
A flaw in the Feast operator allows a malicious tenant to inject arbitrary code into their feature repository. This injected code is executed by an automated process with elevated privileges, potentially enabling the tenant to access sensitive credentials. Such unauthorized access could lead to a significant escalation of privileges, allowing the tenant to gain administrative control over the entire Kubernetes cluster.
Affected Version(s)
Red Hat OpenShift AI 2.25 1786110051
Red Hat OpenShift AI 3.4 1786107278