Privilege Escalation via Code Injection in Feast Operator
CVE-2026-18942 Published on August 10, 2026
Feast-operator: feast: feast apply cronjob runs user python with feature-server sa — tenant code to sa token escalation
A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allowing the tenant to steal sensitive credentials. This could lead to a direct escalation of privileges, granting the tenant administrative control over the Kubernetes cluster.
Vulnerability Analysis
CVE-2026-18942 is exploitable with network access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Timeline
Reported to Red Hat.
Made public. 6 days later.
Weakness Type
What is a Code Injection Vulnerability?
The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVE-2026-18942 has been classified to as a Code Injection vulnerability or weakness.
Products Associated with CVE-2026-18942
Want to know whenever a new CVE is published for Red Hat Openshift Ai? stack.watch will email you.
Affected Versions
Red Hat OpenShift AI 2.25:- Version 1786110051 and below * is unaffected.
- Version 1786107278 and below * is unaffected.