What is CVE-2026-18942?
A critical vulnerability in the Feast operator (CVE-2026-18942) allows a low-privileged tenant to inject arbitrary code into their feature repository, which gets executed by an automated process with elevated privileges. This can lead to theft of sensitive credentials and direct privilege escalation. Users of the Feast operator must immediately apply official patches and harden access controls.
Azərbaycanca: Feast operator-da aşkar edilmiş kritik boşluq (CVE-2026-18942) aşağı etimadlı istifadəçiyə (tenant) öz feature repository-sinə yüksək imtiyazlı proses tərəfindən icra olunan zərərli kod yeritməyə imkan verir. Bu, həssas etimadnamələrin oğurlanmasına və birbaşa imtiyaz yüksəlməsinə səbəb ola bilər. Feast operator istifadəçiləri dərhal rəsmi yamaqları tətbiq etməli və giriş nəzarətlərini sərtləşdirməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ1
What threat does CVE-2026-18942 pose to Feast operator users?
This vulnerability allows a low-privileged tenant to inject malicious code into their feature repository, which is then executed by an automated high-privileged process, potentially leading to theft of sensitive credentials and direct privilege escalation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.