/Vulnerability Library

Feast Feature Server <=0.58.0 - Arbitrary File Read

CVE-2026-23536
Verified

Description

Feast (the open-source Feature Store) Feature Server through 0.58.0 exposes an unauthenticated POST /read-document endpoint that reads an arbitrary, caller-supplied file path with no authentication and no path validation. The read_document_endpoint handler passes the JSON `file_path` field straight to os.path.exists()/open() and returns the file contents in the JSON `content` field, so a remote, unauthenticated attacker can read any file readable by the server process (e.g. /etc/passwd, feature_store.yaml, cloud credentials). Unlike the store-mutating routes it carries no inject_user_details/permission dependency.

Severity

High

CVSS Score

7.5

Exploit Probability

2%

Affected Product

feast

Published Date

August 8, 2026

Template Author

str4k3r

CVE-2026-23536.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-23536
CWE ID:
cwe-22

References

https://access.redhat.com/security/cve/CVE-2026-23536https://bugzilla.redhat.com/show_bug.cgi?id=2429302https://github.com/feast-dev/feasthttps://nvd.nist.gov/vuln/detail/CVE-2026-23536