What is CVE-2026-18941?
CVE-2026-18941 is a flaw found in Feast and feast-operator. The default configuration uses 'no_auth', meaning no security manager is installed. This vulnerability allows unauthenticated and unauthorized access to feature-server, registry-server, and offline-server endpoints. It is critical to review the configuration and enable proper authentication immediately.
Azərbaycanca: CVE-2026-18941, Feast və feast-operator alətlərində aşkar edilmiş boşluqdur. Default konfiqurasiyada 'no_auth' rejimi aktiv olduğu üçün heç bir təhlükəsizlik meneceri quraşdırılmır. Bu zəiflik feature-server, registry-server və offline-server endpoint-lərinə autentifikasiyasız və icazəsiz girişə səbəb olur. Təcili olaraq konfiqurasiyanı yoxlayıb autentifikasiya mexanizmini aktivləşdirmək lazımdır.
Related CVEs
link basis: same weakness class CWE-1188
FAQ2
Which Feast components are affected by CVE-2026-18941?
This vulnerability leads to unauthenticated and unauthorized access to the feature-server, registry-server, and offline-server endpoints.
What is the root cause of CVE-2026-18941?
The default configuration uses 'no_auth' mode, meaning no security manager is installed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.