CVE-2026-92787 PUBLISHED

Feast through 0.66.0 Authentication Bypass via Unverified Token

Assigner: VulnCheck
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor feast-dev
Product feast
Versions Default: unaffected
  • affected from 0 to 0.66.0 (incl.)

Credits

  • George Chen finder

References

Problem Types

  • Use of Hard-coded Credentials CWE