MEDIUM
open-feature
CVE published 2026-09-17
CVE-2026-54495
CVE-2026-54495 debrief: OpenFeature Operator vulnerability allows tenant to access cluster-scoped resources. The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant who can create a controller-owned workload can use the openfeature.dev/featureflagsource annotation with NAMESPACE/NAME syntax to reference a FeatureFlagSource or InProcessConfigura [truncated]