Feast Default no_auth Enables Unauth RCE, DoS, Data Leakage
CVE-2026-18941 Published on August 10, 2026
Feast: feast-operator: feast: default authentication mode is no_auth — shared multi-tenant instances deployed without authentication
A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no security manager is installed. This default allows unauthenticated and unauthorized access to feature-server, registry-server, and offline-server endpoints. A remote attacker, by exploiting this missing authentication, could achieve remote code execution (RCE) by storing a malicious User-Defined Function (UDF) on the feature-server, trigger a denial of service (DoS) by forcing re-materialization of all tenant features, and gain unauthorized access to cross-tenant data.
Vulnerability Analysis
CVE-2026-18941 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Timeline
Reported to Red Hat.
Made public. 6 days later.
Weakness Type
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Products Associated with CVE-2026-18941
Want to know whenever a new CVE is published for Red Hat Openshift Ai? stack.watch will email you.
Affected Versions
Red Hat OpenShift AI 2.25:- Version 1786110051 and below * is unaffected.
- Version 1786110033 and below * is unaffected.
- Version 1786107278 and below * is unaffected.