CVE-2026-23536: Feast: unauthenticated arbitrary file read
A security issue was discovered in the Feast Feature Server's /read-document endpoint that allows an unauthenticated remote attacker to read any file accessible to the server process. By sending a specially crafted HTTP POST request, an attacker can bypass intended access restrictions to potentially retrieve sensitive system files, application configurations, and credentials.
Other sources
Unauthenticated arbitrary file read vulnerability in Feast Feature Server /read-document endpoint allows remote attackers to read any file accessible to the server process without authentication. Version affected: <= 0.58.0
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23536?
CVE-2026-23536 is considered a high severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2026-23536?
To fix CVE-2026-23536, it is recommended to upgrade the Feast Feature Server to version 0.58.1 or later.
Which software is affected by CVE-2026-23536?
CVE-2026-23536 affects the Feast Feature Server version 0.58.0 and earlier.
Can CVE-2026-23536 be exploited remotely?
Yes, CVE-2026-23536 can be exploited by unauthenticated remote attackers.
What type of vulnerability is CVE-2026-23536?
CVE-2026-23536 is classified as an unauthenticated arbitrary file read vulnerability.