Back

HIGH

Feast: unauthenticated arbitrary file read

Published Mar 20, 2026

Description

A security issue was discovered in the Feast Feature Server's `/read-document` endpoint that allows an unauthenticated remote attacker to read any file accessible to the server process. By sending a specially crafted HTTP POST request, an attacker can bypass intended access restrictions to potentially retrieve sensitive system files, application configurations, and credentials.

Affected products

Remediation

Vendor solution

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Red Hat statement

This is an Important vulnerability affecting the Feast Feature Server in Red Hat OpenShift AI (RHOAI). An unauthenticated remote attacker might be able to read arbitrary files accessible to the server process by sending a crafted HTTP POST request to the `/read-document` endpoint.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 20, 2026
Updated Jul 15, 2026
Reserved Jan 13, 2026
CISA Vulnrichment
Updated Mar 24, 2026
NVD
Status Awaiting Analysis
Modified Jul 15, 2026
Red Hat
Severity Important
Public date Mar 20, 2026
ENISA EUVD
Assigner redhat
Published Mar 20, 2026
Updated Jul 15, 2026
Exploited since n/a
EUVD-2026-13816