Feast: unauthenticated arbitrary file read
Published Mar 20, 2026
7.5
HIGHCVSS 3.1
EPSS 2.41%
Description
A security issue was discovered in the Feast Feature Server's `/read-document` endpoint that allows an unauthenticated remote attacker to read any file accessible to the server process. By sending a specially crafted HTTP POST request, an attacker can bypass intended access restrictions to potentially retrieve sensitive system files, application configurations, and credentials.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat OpenShift AI (RHOAI) | affected |
|
No data.
No data.
Red Hat OpenShift AI (RHOAI)
rhoai/odh-feature-server-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-feature-server-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Red Hat statement
This is an Important vulnerability affecting the Feast Feature Server in Red Hat OpenShift AI (RHOAI). An unauthenticated remote attacker might be able to read arbitrary files accessible to the server process by sending a crafted HTTP POST request to the `/read-document` endpoint.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-23536 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2429302 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-13816 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-23536
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23536.json
- https://www.cve.org/CVERecord?id=CVE-2026-23536
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-23536 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2429302 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-13816 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-23536 | ||
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23536.json | ||
| https://www.cve.org/CVERecord?id=CVE-2026-23536 |
Change history (0)
No recorded changes yet.