Deserialization Flaw in Feast Affects Red Hat's Feature Server and Registry
CVE-2026-18948
9.9CRITICAL
What is CVE-2026-18948?
A deserialization flaw found in Feast allows remote attackers to exploit improperly deserialized user-defined functions (UDFs) stored in its registry. This vulnerability can enable unauthenticated arbitrary code execution on the feature server when configured with default settings. Additionally, authenticated attackers may bypass authorization checks, facilitating code execution on the registry server. The implications of this flaw pose risks such as cross-tenant data access and lateral movement within the system, endangering the overall security posture.