CRITICAL 9.3 NVD
CVE-2026-92787
Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by prese
Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server.
References
- https://github.com/feast-dev/feast
- https://github.com/feast-dev/feast/blob/f296d4b/infra/charts/feast-feature-server/template
- https://github.com/feast-dev/feast/blob/f296d4b/sdk/python/feast/permissions/auth/oidc_tok
- https://github.com/feast-dev/feast/blob/v0.66.0/sdk/python/feast/permissions/security_mana
- https://github.com/feast-dev/feast/issues/6785
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-16 via NVD.
Risk Timeline
CVE Disclosed2026-09-16 · -1 days ago
Remediation Resources
vulnfeed aggregates 14597 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.