Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 19 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Feast-dev
Feast-dev feast |
|
| Vendors & Products |
Feast-dev
Feast-dev feast |
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server. | |
| Title | Feast through 0.66.0 Authentication Bypass via Unverified Token | |
| Weaknesses | CWE-798 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-19T01:42:30.616Z
Reserved: 2026-09-16T19:31:52.404Z
Link: CVE-2026-92787
Updated: 2026-09-19T01:42:19.739Z
Status : Received
Published: 2026-09-16T21:17:28.023
Modified: 2026-09-19T02:16:54.547
Link: CVE-2026-92787
No data.
OpenCVE Enrichment
Updated: 2026-09-18T19:00:06Z