PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18948 Red Hat CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T21:17:21.290Z and has not been modified since then. CVE-2026-18948 is a critical vulnerability in Feast that allows unauthenticated remote code execution via improperly deserialized user-defined functions (UDFs). The flaw exists due to insecure deserialization using the 'dill' library. An attacker can store a malicious UDF to achieve code execution on the feature server in default configurations. Authenticated attackers can also bypass authorization to execute code on the registry server. This can lead to cross-tenant data access and lateral movement within the system. Organizations using Feast should prioritize patching and review UDF registry configurations. Evidence from Red Hat suggests affected configurations and potential lateral movement. Defenders should verify UDF registry configurations, monitor for suspicious activity, and review compensating controls for cross-tenant data access.

Vendor
Red Hat
Product
Red Hat OpenShift AI 2.25
CVSS
CRITICAL 9.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-08-27
Advisory published
2026-08-10
Advisory updated
2026-08-27

Who should care

Organizations using Feast for feature serving and machine learning should prioritize patching and review UDF registry configurations to prevent potential code execution and data access. Affected operators, platform administrators, vulnerability management teams, and security teams should be aware of the potential impact and take necessary actions to mitigate the vulnerability.

Technical summary

CVE-2026-18948 is a critical vulnerability in Feast that allows unauthenticated remote code execution via improperly deserialized user-defined functions (UDFs). The flaw exists due to insecure deserialization using the 'dill' library. An attacker can store a malicious UDF to achieve code execution on the feature server in default configurations. Authenticated attackers can also bypass authorization to execute code on the registry server. This can lead to cross-tenant data access and lateral movement within the system.

Defensive priority

Organizations using Feast should prioritize patching and review UDF registry configurations.

Recommended defensive actions

  • Review and patch Feast installations to address UDF deserialization vulnerability
  • Restrict access to the feature server and registry server
  • Monitor for suspicious UDF registry activity
  • Implement compensating controls for cross-tenant data access
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE-2026-18948 flaw in Feast allows remote attackers to execute arbitrary code via improperly deserialized user-defined functions. Evidence from Red Hat suggests affected configurations and potential lateral movement. Defenders should verify UDF registry configurations, monitor for suspicious activity, and review compensating controls for cross-tenant data access. Red Hat errata details provide additional context for affected systems and potential mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-18948 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-18948

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-18948 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18948

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.