Red Hat OpenShift AI (RHOAI): missing authentication
High7.7CVE-2026-18941 · Published Aug 10, 2026 · updated Aug 14, 2026
A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no security manager is installed. This default allows unauthenticated and unauthorized access to feature-server, registry-server, and offline-server endpoints. A remote attacker, by exploiting this missing authentication, could achieve remote code execution (RCE) by storing a malicious User-Defined Function (UDF) on the feature-server, trigger a denial of service (DoS) by forcing re-materialization of all tenant features, and gain unauthorized access to cross-tenant data.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat OpenShift AI (RHOAI) Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet | |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-306
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 10 | Red Hat QEMU: memory corruption | Medium4.4 | No fix yet |
| Aug 10 | Red Hat Enterprise Linux: denial of service | Low3.9 | No fix yet |
| Aug 10 | Red Hat Enterprise Linux 10: privilege escalation | High7.8 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): denial of service | High8.5 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): remote code execution | Critical9.9 | No fix yet |
| Aug 10 | Red Hat OpenShift AI (RHOAI): privilege escalation | High8.8 | No fix yet |