ThreatCluster

Critical Authentication Flaw in Feast SDK and Operator Exposes Systems to RCE

First seen 11 Aug 2026, 08:07 UTC Nvd.Nistaccess.redhat.comcve.org 84% similarity 72

Article Content

Browse articles
ThreatCluster

A significant vulnerability, CVE-2026-18941, was identified in Feast and feast-operator due to the default 'no_auth' configuration, allowing unauthenticated access to critical endpoints. This flaw affects Red Hat OpenShift AI and could enable remote code execution (RCE) through malicious User-Defined Functions (UDFs), denial of service (DoS) attacks, and unauthorized access to cross-tenant data. The vulnerability impacts feature-server, registry-server, and offline-server endpoints, making it a serious concern for users operating in multi-tenant environments. To mitigate this risk, users are advised to implement Kubernetes RBAC authentication and avoid the 'no_auth' setting in production. The CVE was published on August 10, 2026, and remains a high priority for remediation.

Key Points: • CVE-2026-18941 allows unauthenticated access to Feast services, posing severe risks. • Remote code execution and denial of service attacks are possible due to the flaw. • Mitigation requires configuring Kubernetes RBAC authentication for Feast deployments.

ThreatCluster AI How this analysis works

Timeline

2026-08-10
CVE-2026-18941 published
A flaw in Feast and feast-operator was disclosed, allowing unauthenticated access and potential RCE.
Nvd.Nist
2026-08-11
Red Hat issues advisory on CVE-2026-18941
Red Hat confirmed the vulnerability affects OpenShift AI and provided mitigation steps for users.
access.redhat.com

Community

Browse all →

Tracked Entities in This Story