Authorization Bypass Vulnerability in Feast Affects Red Hat Products
CVE-2026-18947

8.5HIGH

What is CVE-2026-18947?

An authorization bypass vulnerability exists within the Feast service, specifically in the /materialize and /materialize-incremental endpoints. Attackers can exploit this flaw by sending a carefully crafted request that omits the feature_views field, allowing them to bypass the intended permission checks. This poses a significant risk, enabling unauthorized users to forcibly trigger a full re-materialization of all feature views. The potential consequences include a Denial of Service (DoS) attack, which can lead to data corruption and excessive resource consumption across all affected tenants.

Affected Version(s)

Red Hat OpenShift AI 2.25 1786110051

Red Hat OpenShift AI 3.3 1786110033

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.