<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:feast:feast:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3afeastfeast/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 21:51:39 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3afeastfeast/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>JWT Authentication Bypass in Feast</title><link>https://feed.craftedsignal.io/briefs/2026-09-feast-jwt-bypass/</link><pubDate>Wed, 16 Sep 2026 21:51:39 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-feast-jwt-bypass/</guid><description>Feast versions 0.66.0 and earlier fail to verify JWT signatures, allowing attackers to bypass RBAC and gain unauthorized read and write access.</description><content:encoded><![CDATA[<p>Feast versions 0.66.0 and earlier contain a critical authentication vulnerability (CVE-2026-92787) due to a failure to verify JSON Web Token (JWT) signatures before establishing user identity. By crafting a JWT with specific, unverified claim values, an unauthenticated attacker can effectively spoof any identity, including administrative accounts. This flaw bypasses all role-based access control (RBAC) mechanisms implemented within the platform.</p>
<p>Successful exploitation allows an attacker to interact with the Feast server as a trusted internal entity, granting them unrestricted read and write permissions to all managed entities, feature views, data sources, and system-level permission policies. Given the nature of Feast as a feature store often central to machine learning pipelines, this vulnerability poses a significant risk to data integrity and unauthorized access to sensitive feature engineering workflows.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full administrative control over the Feast server. An attacker can modify feature definitions, poison training data sources, or exfiltrate sensitive feature metadata. This impacts organizations relying on Feast for ML production environments, potentially leading to unauthorized manipulation of model features and widespread data exposure across the machine learning lifecycle.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Feast to version 0.66.1 or the latest available release immediately to address CVE-2026-92787.</li>
<li>Implement strict network-level access controls to limit access to the Feast server to authorized internal subnets only.</li>
<li>Review audit logs for anomalous account activity or unauthorized modifications to feature views and entities, particularly if performed by service accounts or newly created identities.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>