Authentication Bypass Vulnerability in Feast by Feast Dev
CVE-2026-92787
9.3CRITICAL
What is CVE-2026-92787?
The Feast product from Feast Dev has a security flaw in version 0.66.0, where it fails to verify JSON Web Token (JWT) signatures before determining user identity. This oversight allows malicious entities to bypass role-based access control mechanisms by submitting an unverified token containing a hardcoded claim value. As a result, attackers can seize trusted internal identities, thus gaining unrestricted read and write access to all resources, including entities, feature views, data sources, and permission policies hosted on the server.
Affected Version(s)
feast 0 <= 0.66.0
