Vulnerability Description
A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allowing the tenant to steal sensitive credentials. This could lead to a direct escalation of privileges, granting the tenant administrative control over the Kubernetes cluster.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2026:53261
- https://access.redhat.com/errata/RHSA-2026:53262
- https://access.redhat.com/security/cve/CVE-2026-18942
- https://bugzilla.redhat.com/show_bug.cgi?id=2511118
FAQ
What is CVE-2026-18942?
CVE-2026-18942 is a vulnerability with a CVSS score of 5.5 (MEDIUM). A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allo...
How severe is CVE-2026-18942?
CVE-2026-18942 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-18942?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.