Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-92787: Feast 0.66 lets attackers use fake token to gain access
CVE-2026-92787 · published 23 days ago
Summary
Feast version 0.66 does not check the digital signature on authentication tokens, so anyone can present a crafted token and be treated as an authorized user. This lets the attacker read or change any data, feature definitions, or permission settings stored on the Feast server. Upgrade to a newer Feast release or apply the vendor’s patch that adds proper token verification.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| feast-dev | feast | <= 0.66.0 |
Original advisory text
Feast through 0.66.0 Authentication Bypass via Unverified Token
Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92787... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-92787 Vendor Advisory
- https://github.com/feast-dev/feast
- https://github.com/feast-dev/feast/issues/6785
- https://www.vulncheck.com/advisories/feast-through-0.66.0-authentication-bypass-...
- https://github.com/feast-dev/feast/blob/f296d4b/infra/charts/feast-feature-serve...
- https://github.com/feast-dev/feast/blob/f296d4b/sdk/python/feast/permissions/aut...
- https://github.com/feast-dev/feast/blob/v0.66.0/sdk/python/feast/permissions/sec...
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.3
Critical
Type
CWE-798Use of Hard-coded Credentials
Timeline
Published16 Sep 2026
Updated9 Oct 2026
First seen16 Sep 2026
Track software like this
Free during beta