AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18947

HIGH · CVSS 8.5 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

An authorization bypass vulnerability in Feast's /materialize and /materialize-incremental endpoints allows attackers to circumvent permission checks by sending specially crafted requests that omit the feature_views field. This can lead to a Denial of Service (DoS) through data corruption and excessive resource consumption, affecting all tenants. Organizations using Feast should prioritize addressing this vulnerability to prevent potential service disruptions and resource exhaustion.

CVE
CVE-2026-18947
Severity
HIGH
CVSS
8.5
EPSS
0.43%

Original NVD Description

A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views field, an attacker can bypass intended permission checks. This allows an unauthenticated remote attacker, or any authenticated user, to trigger a full re-materialization of all feature views. The consequence is a Denial of Service (DoS) due to data corruption and significant resource consumption across all tenants.