Description
Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server.
Published: 2026-09-16
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass and Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Feast 0.66.0 and earlier modules incorrectly accept JWT tokens without verifying their cryptographic signatures. The resulting authentication bypass allows an attacker to impersonate any user, granting complete visibility and write access to all managed entities, feature views, data sources, and permission policies. This flaw is a direct violation of role‑based access control and effectively lets an attacker take full control of the Feast server.

Affected Systems

Feast (feast-dev:feast) versions up to and including 0.66.0.

Risk and Exploitability

The nominal severity is high, with a CVSS score of 9.3, and the EPSS score of less than 1% suggests a currently low probability of exploitation. The flaw is not listed in the CISA KEV catalog, but the attack vector is inferred to be remote through the Feast API or any exposed authentication endpoint where an attacker can inject a forged token. The vulnerability’s weakness is described by CWE‑798, representing an improper verification of token signatures.

Generated by OpenCVE AI on September 18, 2026 at 05:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Feast to version 0.66.1 or later, which enforces proper JWT signature verification.
  • Validate that the deployment configuration enforces signature checks and removes any hardcoded claim overrides in the OID token parsing logic.
  • Monitor authentication logs for anomalous token usage and restrict network access to the Feast API to trusted hosts.

Generated by OpenCVE AI on September 18, 2026 at 05:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Feast-dev
Feast-dev feast
Vendors & Products Feast-dev
Feast-dev feast

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server.
Title Feast through 0.66.0 Authentication Bypass via Unverified Token
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T01:42:30.616Z

Reserved: 2026-09-16T19:31:52.404Z

Link: CVE-2026-92787

cve-icon Vulnrichment

Updated: 2026-09-19T01:42:19.739Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:28.023

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-92787

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T19:00:06Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials