CVE-2026-18947: Vulnerability in Red Hat Red Hat OpenShift AI (RHOAI)
CVE-2026-18947 is an authorization bypass vulnerability in the Feast feature server component of Red Hat OpenShift AI (RHOAI). The flaw exists in the /materialize and /materialize-incremental endpoints, where omitting the feature_views field in a request allows bypassing permission checks. This enables unauthenticated or authenticated users to trigger a full re-materialization of all feature views, causing denial of service through data corruption and high resource consumption.
AI Analysis
Technical Summary
A vulnerability in Feast, as deployed in Red Hat OpenShift AI (RHOAI), allows an attacker to bypass authorization checks on the /materialize and /materialize-incremental endpoints by sending a specially crafted request that omits the feature_views field. This bypass enables an unauthenticated remote attacker (in default no_auth configurations) or any authenticated user to trigger a full re-materialization of all feature views. The resulting impact is a denial of service due to data corruption and significant resource consumption affecting all tenants. The vulnerability has a CVSS v3.1 score of 8.5, indicating high severity. The vendor advisory recommends restricting network access to trusted clients and enabling authentication mechanisms such as Kubernetes/OIDC to mitigate unauthenticated exploitation, although authenticated users can still trigger the denial of service.
Potential Impact
The vulnerability allows bypassing intended authorization controls, enabling unauthorized triggering of a full re-materialization process. This leads to denial of service conditions caused by data corruption and excessive resource consumption across all tenants. Both unauthenticated attackers (if no authentication is configured) and authenticated users can exploit this flaw. There is no confidentiality impact, but integrity is highly impacted, and availability is affected at a low level due to denial of service.
Mitigation Recommendations
Red Hat advises restricting network access to the Feast feature server to trusted clients using firewall rules or network policies. If the Feast server is configured with the default no_auth setting, enabling Kubernetes or OIDC authentication is recommended to require user authentication and prevent unauthenticated exploitation. However, because the authorization bypass still allows any authenticated user to trigger the denial of service, additional access controls or usage restrictions should be considered. No official patch or fix is currently confirmed; users should monitor the vendor advisory for updates.
CVE-2026-18947: Vulnerability in Red Hat Red Hat OpenShift AI (RHOAI)
Description
CVE-2026-18947 is an authorization bypass vulnerability in the Feast feature server component of Red Hat OpenShift AI (RHOAI). The flaw exists in the /materialize and /materialize-incremental endpoints, where omitting the feature_views field in a request allows bypassing permission checks. This enables unauthenticated or authenticated users to trigger a full re-materialization of all feature views, causing denial of service through data corruption and high resource consumption.
CVSS v3.1
Score 8.5high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A vulnerability in Feast, as deployed in Red Hat OpenShift AI (RHOAI), allows an attacker to bypass authorization checks on the /materialize and /materialize-incremental endpoints by sending a specially crafted request that omits the feature_views field. This bypass enables an unauthenticated remote attacker (in default no_auth configurations) or any authenticated user to trigger a full re-materialization of all feature views. The resulting impact is a denial of service due to data corruption and significant resource consumption affecting all tenants. The vulnerability has a CVSS v3.1 score of 8.5, indicating high severity. The vendor advisory recommends restricting network access to trusted clients and enabling authentication mechanisms such as Kubernetes/OIDC to mitigate unauthenticated exploitation, although authenticated users can still trigger the denial of service.
Potential Impact
The vulnerability allows bypassing intended authorization controls, enabling unauthorized triggering of a full re-materialization process. This leads to denial of service conditions caused by data corruption and excessive resource consumption across all tenants. Both unauthenticated attackers (if no authentication is configured) and authenticated users can exploit this flaw. There is no confidentiality impact, but integrity is highly impacted, and availability is affected at a low level due to denial of service.
Mitigation Recommendations
Red Hat advises restricting network access to the Feast feature server to trusted clients using firewall rules or network policies. If the Feast server is configured with the default no_auth setting, enabling Kubernetes or OIDC authentication is recommended to require user authentication and prevent unauthenticated exploitation. However, because the authorization bypass still allows any authenticated user to trigger the denial of service, additional access controls or usage restrictions should be considered. No official patch or fix is currently confirmed; users should monitor the vendor advisory for updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-08-05T13:33:36.903Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-18947","vendor":"Red Hat"}]
Threat ID: 6a7a3b16bf8831d539856686
Added to database: 08/10/2026, 20:56:54 UTC
Last enriched: 08/10/2026, 21:12:23 UTC
Last updated: 08/11/2026, 03:59:19 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.