{"id":"CVE-2026-92787","summary":"Feast through 0.66.0 Authentication Bypass via Unverified Token","details":"Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server.","modified":"2026-09-18T03:48:43.072608663Z","published":"2026-09-16T20:32:43.913Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-798"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92787.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92787.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92787"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/feast-through-0.66.0-authentication-bypass-via-unverified-token"},{"type":"REPORT","url":"https://github.com/feast-dev/feast/issues/6785"},{"type":"PACKAGE","url":"https://github.com/feast-dev/feast"},{"type":"ARTICLE","url":"https://github.com/feast-dev/feast/blob/f296d4b/infra/charts/feast-feature-server/templates/deployment.yaml#L46-L47"},{"type":"ARTICLE","url":"https://github.com/feast-dev/feast/blob/f296d4b/sdk/python/feast/permissions/auth/oidc_token_parser.py#L152-L156"},{"type":"ARTICLE","url":"https://github.com/feast-dev/feast/blob/v0.66.0/sdk/python/feast/permissions/security_manager.py#L248-L264"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/feast-dev/feast","events":[{"introduced":"0"},{"fixed":"1d5be950cf718a674cb01eaf0fd0ad6f0a4c6335"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0.66.0"},{"fixed":"0.66.0"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["v0.65.0","v0.64.0","v0.63.0","v0.62.0","v0.60.0","v0.59.0","v0.58.0","v0.54.0","v0.57.0","v0.56.0","v0.55.0","v0.53.0","v0.52.0","v0.51.0","v0.50.0","v0.49.0","v0.48.0","v0.47.0","v0.46.0","v0.45.0","v0.44.0","v0.43.0","v0.42.0","v0.41.0","v0.40.0","v0.39.0","v0.38.0","v0.37.0","v0.36.0","v0.35.0","v0.34.0","v0.33.0","v0.32.0","v0.31.0","v0.30.0","v0.29.0","v0.28.0","v0.27.0","v0.26.0","v0.25.0","v0.24.0","v0.23.0","v0.22.0","v0.21.0","v0.20.0","v0.19.0","v0.18.0","v0.17.0","v0.16.0","v0.14.0","v0.13.0","v0.12.0","v0.11.0","v0.10.0","v0.9.0-rc.2","v0.9.0-rc.1","v0.8.0","sdk/go/v0.8.0","v0.8.0-rc.3","v0.8.0-rc.2","v0.8.0-rc.1","v0.6.0","v0.5.0","v0.4.2","v0.4.1","v0.4.0","v0.3.2","v0.3.0","v0.1.1","v0.1.0","v0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92787.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}