Deserialization Flaw in Feast Affects Red Hat's Feature Server and Registry
CVE-2026-18948

9.9CRITICAL

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
10 August 2026

What is CVE-2026-18948?

A deserialization flaw found in Feast allows remote attackers to exploit improperly deserialized user-defined functions (UDFs) stored in its registry. This vulnerability can enable unauthenticated arbitrary code execution on the feature server when configured with default settings. Additionally, authenticated attackers may bypass authorization checks, facilitating code execution on the registry server. The implications of this flaw pose risks such as cross-tenant data access and lateral movement within the system, endangering the overall security posture.

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.