CVE-2026-18941
7.7Red Hat · OpenShift AI
A vulnerability in the Feast and feast-operator components of Red Hat OpenShift AI 3.3 allows for unauthorized access due to missing authentication.
Executive summary
A high-severity authentication bypass in the Feast operator of Red Hat OpenShift AI 3.3 could allow attackers to access sensitive data across the platform.
Vulnerability
This issue involves missing authentication for critical functions (CWE-306) within Feast and the feast-operator. The CVSS vector (PR:L/S:C) confirms that a low-privileged user can exploit this to achieve a scope change, potentially leading to unauthorized information disclosure.
Business impact
The ability to bypass authentication in the Feast component allows for the unauthorized extraction of potentially sensitive feature data. With a CVSS score of 7.7, the risk of data exfiltration is substantial, which could lead to severe privacy violations and regulatory non-compliance depending on the nature of the data stored in the feature store.
Remediation
Immediate Action: Update the affected software to the version fixed in build/release 1786110033 or later, as referenced in RHSA-2026:53263.
Proactive Monitoring: Audit access logs for the Feast service to identify any unauthorized queries or access patterns that deviate from standard operational behavior.
Compensating Controls: Implement network-level restrictions or service mesh policies to enforce authentication and authorization at the ingress points for the Feast services.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Addressing this vulnerability is essential to maintain the security boundary of the feature store. Administrators should verify their current versions against the fixed release and apply the necessary patches without delay to prevent unauthorized data access.