A flaw was found in the Feast operator. A malicious...
Moderate severity
Unreviewed
Published
Aug 10, 2026
to the GitHub Advisory Database
•
Updated Aug 12, 2026
Description
Published by the National Vulnerability Database
Aug 10, 2026
Published to the GitHub Advisory Database
Aug 10, 2026
Last updated
Aug 12, 2026
A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allowing the tenant to steal sensitive credentials. This could lead to a direct escalation of privileges, granting the tenant administrative control over the Kubernetes cluster.
References