CVE-2026-23536
Awaiting Analysis Awaiting Analysis - Queue

Unauthorized File Read via Feast Feature Server `/read-document` Endpoint

Vulnerability report for CVE-2026-23536, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-03-20

Last updated on: 2026-07-15

Assigner: Red Hat, Inc.

Description

A security issue was discovered in the Feast Feature Server's `/read-document` endpoint that allows an unauthenticated remote attacker to read any file accessible to the server process. By sending a specially crafted HTTP POST request, an attacker can bypass intended access restrictions to potentially retrieve sensitive system files, application configurations, and credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-03-20
Last Modified
2026-07-15
Generated
2026-07-26
AI Q&A
2026-03-21
EPSS Evaluated
2026-07-25
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
feast feature_server to 0.58.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in the Feast Feature Server's `/read-document` endpoint. It allows an unauthenticated remote attacker to read any file that the server process has access to. By sending a specially crafted HTTP POST request, the attacker can bypass the intended access restrictions.

As a result, the attacker may retrieve sensitive system files, application configurations, and credentials.

Detection Guidance

I don't know

Impact Analysis

The impact of this vulnerability is that an attacker can access sensitive information stored on the server without any authentication.

  • Exposure of sensitive system files
  • Disclosure of application configuration files
  • Leakage of credentials

This can lead to further attacks, data breaches, and compromise of the affected system.

Compliance Impact

I don't know

Mitigation Strategies

I don't know

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-23536. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart