What is CVE-2026-18947?
A critical authorization bypass vulnerability was found in the Feast feature store platform. By sending specially crafted requests omitting the feature_views field to the /materialize and /materialize-incremental endpoints, an unauthenticated remote attacker can bypass permission checks. Administrators must immediately update Feast to the latest version or temporarily restrict access to these endpoints.
Azərbaycanca: Feast açıq mənbəli feature store platformasında ciddi bir avtorizasiya boşluğu aşkar edilib. /materialize və /materialize-incremental API endpointlərinə göndərilən xüsusi hazırlanmış sorğularla autentifikasiya olunmamış uzaqdan hücum edən şəxs icazə yoxlamalarını keçə bilər. Təsirlənən sistemlərin inzibatçıları dərhal Feast-i ən son versiyaya yeniləməli və ya müvəqqəti olaraq bu endpointlərə girişi məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What does CVE-2026-18947 allow an unauthenticated attacker to do in Feast?
The attacker can bypass permission checks by sending specially crafted requests to the /materialize and /materialize-incremental API endpoints.
What mitigation steps should Feast administrators take for CVE-2026-18947?
They must immediately update Feast to the latest version or temporarily restrict access to these endpoints.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.