{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3afeastfeast/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:feast:feast:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Feast (\u003c= 0.66.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Feast"],"content_html":"\u003cp\u003eFeast versions 0.66.0 and earlier contain a critical authentication vulnerability (CVE-2026-92787) due to a failure to verify JSON Web Token (JWT) signatures before establishing user identity. By crafting a JWT with specific, unverified claim values, an unauthenticated attacker can effectively spoof any identity, including administrative accounts. This flaw bypasses all role-based access control (RBAC) mechanisms implemented within the platform.\u003c/p\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to interact with the Feast server as a trusted internal entity, granting them unrestricted read and write permissions to all managed entities, feature views, data sources, and system-level permission policies. Given the nature of Feast as a feature store often central to machine learning pipelines, this vulnerability poses a significant risk to data integrity and unauthorized access to sensitive feature engineering workflows.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full administrative control over the Feast server. An attacker can modify feature definitions, poison training data sources, or exfiltrate sensitive feature metadata. This impacts organizations relying on Feast for ML production environments, potentially leading to unauthorized manipulation of model features and widespread data exposure across the machine learning lifecycle.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Feast to version 0.66.1 or the latest available release immediately to address CVE-2026-92787.\u003c/li\u003e\n\u003cli\u003eImplement strict network-level access controls to limit access to the Feast server to authorized internal subnets only.\u003c/li\u003e\n\u003cli\u003eReview audit logs for anomalous account activity or unauthorized modifications to feature views and entities, particularly if performed by service accounts or newly created identities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T21:51:39Z","date_published":"2026-09-16T21:51:39Z","id":"https://feed.craftedsignal.io/briefs/2026-09-feast-jwt-bypass/","summary":"Feast versions 0.66.0 and earlier fail to verify JWT signatures, allowing attackers to bypass RBAC and gain unauthorized read and write access.","title":"JWT Authentication Bypass in Feast","url":"https://feed.craftedsignal.io/briefs/2026-09-feast-jwt-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:feast:feast:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}