CVE-2026-18942 MEDIUM

CVE-2026-18942: Feast-operator: feast: feast apply cronjob runs user python with feature-server sa — tenant code to sa token escalation

Vendor Red Hat
Product Red Hat OpenShift AI (RHOAI)
Published August 10, 2026
Last update August 19, 2026

CVSS base score

5.5/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:L

What the vulnerability does

01Description

A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allowing the tenant to steal sensitive credentials. This could lead to a direct escalation of privileges, granting the tenant administrative control over the Kubernetes cluster.

Key dates

02Disclosure timeline

August 10, 2026 CVE published
August 19, 2026 Record updated