PT-2026-26683 · Unknown · Feast Feature Server
Jitendra Yejare
·
Published
2026-03-20
·
Updated
2026-03-21
·
CVE-2026-23536
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Feast Feature Server (affected versions not specified)
Description
A security issue exists in the Feast Feature Server that allows an unauthenticated remote attacker to read any file accessible to the server process. This is exploitable through the
/read-document API endpoint by sending a specially crafted HTTP POST request, bypassing intended access restrictions. This could lead to the retrieval of sensitive system files, application configurations, and credentials. The root cause is flawed access controls. Exploitation of this issue can enable low-privileged users to gain cluster admin rights, potentially leading to full hybrid cloud compromise, data exfiltration, and AI workload disruption.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Feast Feature Server