Authorization Bypass Vulnerability in Feast Affects Red Hat Products
CVE-2026-18947
8.5HIGH
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 10 August 2026
What is CVE-2026-18947?
An authorization bypass vulnerability exists within the Feast service, specifically in the /materialize and /materialize-incremental endpoints. Attackers can exploit this flaw by sending a carefully crafted request that omits the feature_views field, allowing them to bypass the intended permission checks. This poses a significant risk, enabling unauthorized users to forcibly trigger a full re-materialization of all feature views. The potential consequences include a Denial of Service (DoS) attack, which can lead to data corruption and excessive resource consumption across all affected tenants.
Affected Version(s)
Red Hat OpenShift AI 2.25 1786110051
Red Hat OpenShift AI 3.3 1786110033