CVE-2026-18942
A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be exe
CVSS
5.5
Medium
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Published: Aug 10, 2026 · Last modified: Aug 19, 2026 · CWE-94
0.3%EPSS · 30 days0.3%
2026-08-132026-09-10
A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allowing the tenant to steal sensitive credentials. This could lead to a direct escalation of privileges, granting the tenant administrative control over the Kubernetes cluster.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-1456010.0 CRI—
——0The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the server.3hCVE-2026-819408.8 HIG—
——0IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.16hCVE-2026-812049.8 CRI—
——0IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.16hCVE-2026-797428.8 HIG—
——0IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.16hCVE-2026-785718.8 HIG—
——0IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.16hCVE-2026-91766.7 MED—
——0IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources.17h