Code Injection Vulnerability in Feast Operator by Red Hat
CVE-2026-18942

5.5MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
10 August 2026

What is CVE-2026-18942?

A flaw in the Feast operator allows a malicious tenant to inject arbitrary code into their feature repository. This injected code is executed by an automated process with elevated privileges, potentially enabling the tenant to access sensitive credentials. Such unauthorized access could lead to a significant escalation of privileges, allowing the tenant to gain administrative control over the entire Kubernetes cluster.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.