A flaw was found in the Feast operator. (CVE-2026-18942)
A vulnerability in the Feast operator allows a malicious tenant to inject arbitrary code into their feature repository. This code is executed by an automated process with elevated privileges, enabling the tenant to steal sensitive credentials and escalate privileges to gain administrative control over the Kubernetes cluster. The CVSS score is 5.5, indicating a medium severity level. No known exploits are reported in the wild. The vendor advisory from Red Hat does not explicitly mention a fix for this specific CVE but provides updated images and instructions for upgrading Red Hat OpenShift AI components.
AI Analysis
Technical Summary
CVE-2026-18942 describes a flaw in the Feast operator where a malicious tenant can inject arbitrary code into their feature repository. This code is executed by an automated process running with elevated privileges, which can lead to theft of sensitive credentials and privilege escalation to administrative control over the Kubernetes cluster. The vulnerability has a CVSS 3.1 base score of 5.5, with network attack vector, high attack complexity, and requires high privileges but no user interaction. The vendor advisory from Red Hat references this CVE as part of a broader set of vulnerabilities affecting Red Hat OpenShift AI but does not explicitly state a patch or fix for this CVE alone. Updated images for Red Hat OpenShift AI are available, and users are directed to upgrade their clusters following vendor documentation.
Potential Impact
Successful exploitation allows a malicious tenant to execute arbitrary code with elevated privileges, steal sensitive credentials, and escalate privileges to gain administrative control over the Kubernetes cluster. This can compromise cluster integrity and confidentiality. The medium CVSS score reflects the requirement for high privileges and attack complexity, but the impact on confidentiality is high and availability is low.
Mitigation Recommendations
The vendor advisory does not explicitly state a direct fix for CVE-2026-18942 but provides updated images for Red Hat OpenShift AI and instructions for upgrading clusters. Users should follow the official Red Hat OpenShift AI upgrade documentation to apply the latest updates. Patch status is not explicitly confirmed for this CVE alone; therefore, check the vendor advisory regularly for updated remediation guidance.
A flaw was found in the Feast operator. (CVE-2026-18942)
Description
A vulnerability in the Feast operator allows a malicious tenant to inject arbitrary code into their feature repository. This code is executed by an automated process with elevated privileges, enabling the tenant to steal sensitive credentials and escalate privileges to gain administrative control over the Kubernetes cluster. The CVSS score is 5.5, indicating a medium severity level. No known exploits are reported in the wild. The vendor advisory from Red Hat does not explicitly mention a fix for this specific CVE but provides updated images and instructions for upgrading Red Hat OpenShift AI components.
CVSS v3.1
Score 5.5medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-18942 describes a flaw in the Feast operator where a malicious tenant can inject arbitrary code into their feature repository. This code is executed by an automated process running with elevated privileges, which can lead to theft of sensitive credentials and privilege escalation to administrative control over the Kubernetes cluster. The vulnerability has a CVSS 3.1 base score of 5.5, with network attack vector, high attack complexity, and requires high privileges but no user interaction. The vendor advisory from Red Hat references this CVE as part of a broader set of vulnerabilities affecting Red Hat OpenShift AI but does not explicitly state a patch or fix for this CVE alone. Updated images for Red Hat OpenShift AI are available, and users are directed to upgrade their clusters following vendor documentation.
Potential Impact
Successful exploitation allows a malicious tenant to execute arbitrary code with elevated privileges, steal sensitive credentials, and escalate privileges to gain administrative control over the Kubernetes cluster. This can compromise cluster integrity and confidentiality. The medium CVSS score reflects the requirement for high privileges and attack complexity, but the impact on confidentiality is high and availability is low.
Mitigation Recommendations
The vendor advisory does not explicitly state a direct fix for CVE-2026-18942 but provides updated images for Red Hat OpenShift AI and instructions for upgrading clusters. Users should follow the official Red Hat OpenShift AI upgrade documentation to apply the latest updates. Patch status is not explicitly confirmed for this CVE alone; therefore, check the vendor advisory regularly for updated remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-55p8-2553-ch47
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-18942"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Patch Information
Threat ID: 6a7c9b73bf8831d539ce0bea
Added to database: 08/12/2026, 16:12:35 UTC
Last enriched: 08/12/2026, 16:28:02 UTC
Last updated: 08/12/2026, 16:40:59 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.