Authentication Bypass Vulnerability in Feast by Feast Dev
CVE-2026-92787

9.3CRITICAL

Key Information:

Vendor

Feast-dev

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92787?

The Feast product from Feast Dev has a security flaw in version 0.66.0, where it fails to verify JSON Web Token (JWT) signatures before determining user identity. This oversight allows malicious entities to bypass role-based access control mechanisms by submitting an unverified token containing a hardcoded claim value. As a result, attackers can seize trusted internal identities, thus gaining unrestricted read and write access to all resources, including entities, feature views, data sources, and permission policies hosted on the server.

Affected Version(s)

feast 0 <= 0.66.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.