HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-18947 — A flaw was found in Feast. An authorization bypass vulnerability exists in the /...

·Source: NIST NVD

Updated:

Executive Summary

A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views field, an attacker can bypass intended permission checks. This allows an unauthenticated remote attacker, or any authenticated user, to trigger a full re-materialization of all feature views. The cons

Analysis

A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views field, an attacker can bypass intended permission checks. This allows an unauthenticated remote attacker, or any authenticated user, to trigger a full re-materialization of all feature views. The consequence is a Denial of Service (DoS) due to data corruption and significant resource consumption across all tenants. CVSS Score: 8.5. Published: 2026-08-10T21:17:21.130.

Indicators of Compromise (1)

CVE (1)
CVE-2026-18947
Source Attribution

Originally published by NIST NVD on Aug 10, 2026. Verified by: NIST.

Related Threats

MEDIUMVulnerability

NC: Possible cyberattack hits Wake election software vendor, leaving poll workers’ data exposed

Caroline Yaffa reports: The Wake County Board of Elections is suspending its use of a software vendor after it reported a possible cyberattack. There’s no evidence that voting machines, ballots, voter registration records or systems used to count votes were affected, according to the county board. But the incident could have exposed information about people... Source

DataBreaches.net
CRITICALVulnerability

NVD CRITICAL: CVE-2026-73053 — SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in th...

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.

CVE-2026-73053
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-73052 — SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and...

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.

CVE-2026-73052
NIST NVD