CVE-2026-18948

🟠 Łataj w tym tygodniu

Błąd w Feast umożliwia zdalne wykonanie kodu przez nieautoryzowane deserializowanie funkcji.

CVSS
9.9
EPSS
0.7%
Exploit
none
Vendor
Opis źródłowy (NVD)

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the feature server in default configurations. An authenticated attacker can also achieve arbitrary code execution on the registry server by bypassing authorization checks during deserialization. This vulnerability can result in cross-tenant data access and lateral movement within the system.

deserialization rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.9
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.7%
Opublikowano (NVD)2026-08-10 21:17:21 UTC
Ostatnia modyfikacja (NVD)2026-08-14 19:07:46 UTC
Referencje