CVE-2026-18942: Feast operator: code injection escalates to cluster admin

MEDIUM
Published August 10, 2026
CISO Take

A flaw in the Feast feature store operator lets a malicious tenant smuggle arbitrary code into their feature repository, which an automated reconciliation process then runs with elevated service-account privileges — handing the tenant a path from feature-store access to full Kubernetes cluster administration. This matters most in shared MLOps platforms like Red Hat OpenShift AI, where the affected images span pipeline runtimes and Jupyter workbenches used across many teams, so a single rogue or compromised tenant can pivot into infrastructure they were never meant to touch. The practical urgency is limited today: exploitation requires an already-authenticated tenant (PR:H) plus high attack complexity, there's no public exploit or Nuclei template, EPSS sits at 0.00308, it isn't in CISA KEV, and CISA's own SSVC call is TRACK. Apply the vendor patches referenced in RHSA-2026:53261/53262 on your next maintenance window, and in the meantime restrict who can submit feature repositories and review the RBAC scope granted to the Feast operator's service account so a compromised or malicious tenant can't inherit cluster-admin-adjacent permissions.

Sources: NVD access.redhat.com EPSS OpenSSF ATLAS

What is the risk?

Medium severity (CVSS 5.5) reflects a real but constrained risk: confidentiality impact is high (credential theft) while integrity and availability impact are only low, and the attack requires high privileges and high complexity to execute — this is not a remote, unauthenticated bug. The lack of a public exploit, absence from CISA KEV, TRACK-level SSVC decision, and near-floor EPSS score (0.00308) all indicate low near-term exploitation likelihood. However, the blast radius on package popularity (3,744 downstream dependents) and the severity of the end state — cluster administrative control from a tenant-level foothold — mean this should be prioritized for patching in any multi-tenant deployment even though it's not an emergency.

How does the attack unfold?

Initial Access
A tenant with valid but limited credentials submits a feature repository containing malicious code disguised as a feature definition or transformation.
AML.T0012
Execution
The Feast operator's automated reconciliation process executes the tenant's code using its own elevated service account.
AML.T0050
Credential Access
The malicious code reads the operator's service account token and accessible secrets from within the execution pod.
AML.T0055
Impact
The attacker uses the stolen elevated credentials to call the Kubernetes API directly, escalating to administrative control over the cluster.

What systems are affected?

Package Ecosystem Vulnerable Range Patched
TensorFlow pip — No patch
200.5K OpenSSF 7.5 3.4K dependents Pushed 5d ago 4% patched ~1372d to patch Full package profile →
TensorFlow pip — No patch
200.5K OpenSSF 7.5 3.4K dependents Pushed 5d ago 4% patched ~1372d to patch Full package profile →
TensorFlow pip — No patch
200.5K OpenSSF 7.5 3.4K dependents Pushed 5d ago 4% patched ~1372d to patch Full package profile →
TensorFlow pip — No patch
200.5K OpenSSF 7.5 3.4K dependents Pushed 5d ago 4% patched ~1372d to patch Full package profile →
rhoai/odh-feature-server-rhel9 — — No patch
rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9 — — No patch
rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9 — — No patch
rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9 — — No patch
rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9 — — No patch
rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9 — — No patch
rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9 — — No patch
rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9 — — No patch
rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9 — — No patch
rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9 — — No patch

How severe is it?

CVSS 3.1
5.5 / 10
EPSS
0.4%
chance of exploitation in 30 days
Higher than 31% of all CVEs
Exploitation Status
No known exploitation
Sophistication
Moderate

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC High
PR High
UI None
S Unchanged
C High
I Low
A Low

What should I do?

1 step
  1. Patch to the fixed Feast operator / RHOAI component versions referenced in RHSA-2026:53261 and RHSA-2026:53262. Until patched, restrict feature-repository submission to trusted tenants only and audit existing repositories for unexpected code paths (custom transformations, on-apply hooks, init scripts). Review and minimize the RBAC role bound to the Feast operator's service account — it should never carry cluster-admin or near-cluster-admin scope; apply least-privilege and namespace-scoped roles instead. Monitor for anomalous Kubernetes API calls or secret access originating from the feature-store operator's service account, and rotate any credentials that operator has had access to as a precaution after patching.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable No
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Article 15 - Accuracy, robustness and cybersecurity
ISO 42001
A.6.2.4 - AI system deployment
OWASP LLM Top 10
LLM03 - Supply Chain

Frequently Asked Questions

What is CVE-2026-18942?

A flaw in the Feast feature store operator lets a malicious tenant smuggle arbitrary code into their feature repository, which an automated reconciliation process then runs with elevated service-account privileges — handing the tenant a path from feature-store access to full Kubernetes cluster administration. This matters most in shared MLOps platforms like Red Hat OpenShift AI, where the affected images span pipeline runtimes and Jupyter workbenches used across many teams, so a single rogue or compromised tenant can pivot into infrastructure they were never meant to touch. The practical urgency is limited today: exploitation requires an already-authenticated tenant (PR:H) plus high attack complexity, there's no public exploit or Nuclei template, EPSS sits at 0.00308, it isn't in CISA KEV, and CISA's own SSVC call is TRACK. Apply the vendor patches referenced in RHSA-2026:53261/53262 on your next maintenance window, and in the meantime restrict who can submit feature repositories and review the RBAC scope granted to the Feast operator's service account so a compromised or malicious tenant can't inherit cluster-admin-adjacent permissions.

Is CVE-2026-18942 actively exploited?

No confirmed active exploitation of CVE-2026-18942 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-18942?

Patch to the fixed Feast operator / RHOAI component versions referenced in RHSA-2026:53261 and RHSA-2026:53262. Until patched, restrict feature-repository submission to trusted tenants only and audit existing repositories for unexpected code paths (custom transformations, on-apply hooks, init scripts). Review and minimize the RBAC role bound to the Feast operator's service account — it should never carry cluster-admin or near-cluster-admin scope; apply least-privilege and namespace-scoped roles instead. Monitor for anomalous Kubernetes API calls or secret access originating from the feature-store operator's service account, and rotate any credentials that operator has had access to as a precaution after patching.

What systems are affected by CVE-2026-18942?

This vulnerability affects the following AI/ML architecture patterns: feature stores, model serving, training pipelines, MLOps orchestration.

What is the CVSS score for CVE-2026-18942?

CVE-2026-18942 has a CVSS v3.1 base score of 5.5 (MEDIUM). The EPSS exploitation probability is 0.39%.

What is the AI security impact?

Affected AI Architectures

feature storesmodel servingtraining pipelinesMLOps orchestration

MITRE ATLAS Techniques

AML.T0010 AI Supply Chain Compromise
AML.T0050 Command and Scripting Interpreter
AML.T0055 Unsecured Credentials

Compliance Controls Affected

EU AI Act: Article 15
ISO 42001: A.6.2.4
OWASP LLM Top 10: LLM03

What are the technical details?

Original Advisory

A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allowing the tenant to steal sensitive credentials. This could lead to a direct escalation of privileges, granting the tenant administrative control over the Kubernetes cluster.

Exploitation Scenario

A tenant with legitimate but limited access to a shared MLOps platform submits a feature repository containing a malicious Python transformation or hook disguised as a normal feature definition. When the Feast operator's automated reconciliation process picks up the change and runs `feast apply`/materialization, it executes the tenant's code inside a pod using its own elevated service account. That code reads the mounted service account token and any accessible secrets, then uses them to call the Kubernetes API directly — escalating from a single tenant's feature-store permissions to broader cluster control, potentially compromising other tenants' workloads and data.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:L

References

Timeline

Published
August 10, 2026
Last Modified
August 19, 2026
First Seen
August 11, 2026

Related Vulnerabilities