PT-2026-26683 · Red Hat · Red Hat Openshift

Jitendra Yejare

·

Published

2026-03-20

·

Updated

2026-03-20

·

CVE-2026-23536

CVSS v3.1

7.5

High

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
A security issue was discovered in the Feast Feature Server's /read-document endpoint that allows an unauthenticated remote attacker to read any file accessible to the server process. By sending a specially crafted HTTP POST request, an attacker can bypass intended access restrictions to potentially retrieve sensitive system files, application configurations, and credentials.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-23536

Affected Products

Red Hat Openshift