CVE-2026-92787
Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based acc
CVSS
9.8
Crítico
EPSS
0.4%
p31
KEV
—
Exploit Today
9
0-100
Publicado: 16 sept 2026 · Última mod.: 16 sept 2026 · CWE-798
Sin historial EPSS suficiente todavía.
Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server.
- github.comhttps://github.com/feast-dev/feast
- github.comhttps://github.com/feast-dev/feast/blob/f296d4b/infra/charts/feast-feature-server/templates/deployment.yaml#L46-L47
- github.comhttps://github.com/feast-dev/feast/blob/f296d4b/sdk/python/feast/permissions/auth/oidc_token_parser.py#L152-L156
- github.comhttps://github.com/feast-dev/feast/blob/v0.66.0/sdk/python/feast/permissions/security_manager.py#L248-L264
- github.comhttps://github.com/feast-dev/feast/issues/6785
- www.vulncheck.comhttps://www.vulncheck.com/advisories/feast-through-0.66.0-authentication-bypass-via-unverified-token
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-814407.3 ALT—
——0Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.15hCVE-2026-689508.8 ALT13.2%
——4The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.1dCVE-2026-668909.6 CRÍ9.7%
——3The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.1dCVE-2026-371529.8 CRÍ40.2%
——12TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.1dCVE-2026-161418.1 ALT32.9%
——10OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI service then accepts a RAKP Message 3 whose HMAC is computed with the constant 20-byte 'userKey' initialized from the string '0penBmc' and an often-predictable 'bmcRandomNum'. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C.3dCVE-2026-571489.8 CRÍ30.4%
——9PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup and token-issuance guards are disabled because PLATFORM_ENV also defaults to dev. An unauthenticated attacker can sign a JWT containing an attacker-chosen sub value, and AuthService._verify_token() accepts it as an authenticated identity, enabling user or workspace-owner impersonation when a target identifier is known. This vulnerability is fixed in praisonai-platform 0.1.6.1d