CVE-2026-18942
Received Received - Intake

Code Injection Flaw in Feast Operator

Vulnerability report for CVE-2026-18942, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: Red Hat, Inc.

Description

A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allowing the tenant to steal sensitive credentials. This could lead to a direct escalation of privileges, granting the tenant administrative control over the Kubernetes cluster.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Feast operator where a malicious tenant can inject arbitrary code into their feature repository. This code is then executed by an automated process with high privileges, allowing the tenant to steal sensitive credentials and gain administrative control over the Kubernetes cluster.

Impact Analysis

If exploited, this flaw could let an attacker with tenant access steal credentials and escalate privileges to take full control of the Kubernetes cluster. This could lead to unauthorized access to sensitive data, system disruption, or further attacks within the environment.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules. Compliance failures may result in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Immediately restrict tenant access to feature repository modifications and review all automated processes with elevated privileges for unauthorized code execution. Audit Kubernetes cluster permissions and credentials to identify any potential misuse.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18942. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart