CVE-2026-18947

8.5

Red Hat · OpenShift AI

A vulnerability in the Feast component within Red Hat OpenShift AI allows for execution with unnecessary privileges.

Executive summary

A privilege-related vulnerability in the Feast component of Red Hat OpenShift AI poses a significant risk to data integrity and system availability.

Vulnerability

This issue is classified as execution with unnecessary privileges (CWE-250) within the Feast feature store component. An authenticated user with low privileges can exploit this over the network, resulting in a scope change that allows for unauthorized data modification or availability disruption.

Business impact

The CVSS score of 8.5 highlights the critical nature of this vulnerability. Because Feast is used for feature management in machine learning pipelines, unauthorized modification of data could lead to poisoned models or incorrect analytical outputs, causing severe downstream business consequences and reputational damage.

Remediation

Immediate Action: Update Red Hat OpenShift AI 3.3 by installing the update for Feast, specifically version 1786110033 or later as identified in RHSA-2026:53263.

Proactive Monitoring: Review data integrity logs and monitor for unexpected modifications to feature store definitions or ingested data.

Compensating Controls: Utilize network policies to restrict access to the Feast API to only trusted services and authenticated internal users.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Maintaining the integrity of machine learning pipelines is essential for reliable AI operations. Security teams must ensure the Feast component is updated to the specified patched version to mitigate the risk of unauthorized data modification and ensure long-term model reliability.

More Red Hat CVEs