CVE-2026-18948 is a critical security vulnerability affecting Feast, an open-source feature store commonly used to operationalize machine learning data for analytics, recommendation engines, fraud detection, and other artificial intelligence workloads. If your organization runs Feast directly, uses it within a managed or containerized AI platform, or operates Red Hat OpenShift AI environments that include the affected component, this issue deserves prompt executive and technical review.
The risk is not limited to a single application outage. Successful exploitation can give an attacker the ability to run unauthorized commands in parts of your AI infrastructure, potentially exposing data, interrupting production services, or providing a foothold for movement into connected systems. The issue is particularly important for shared or multi-team AI platforms, where a compromise may extend beyond one project or workload.
This post explains the business implications, practical exposure checks, realistic scenarios, and response priorities. A technical appendix follows for security engineers, platform owners, and penetration testers.
CVE-2026-18948 was published on August 10, 2026, after being reported through Red Hat’s security process. The issue affects Feast, an open-source feature store that helps organizations manage and serve machine learning features. Red Hat is the CVE Naming Authority source for the vulnerability, and the National Vulnerability Database lists the record as awaiting further enrichment.
The vulnerability received a Critical severity rating of 9.9 out of 10 under the Common Vulnerability Scoring System. In plain language, Feast can treat stored user-defined functions as trusted when it processes them, even though those functions may have been altered or supplied by an attacker. That unsafe handling can permit unauthorized code to run within Feast services.
The underlying issue was reported in Red Hat Bugzilla on August 4, 2026. Red Hat’s public CVE record identifies impacts on Feast deployments in Red Hat OpenShift AI, while the NVD record was last modified on August 27, 2026. Organizations should follow applicable vendor advisories and determine their specific deployed package and platform exposure rather than relying only on upstream version labels.
For your business, CVE-2026-18948 can turn an AI data-management component into an entry point for a broader compromise. In default Feast configurations described by Red Hat, an external attacker may be able to cause unauthorized code to run on the feature server. In environments where authentication is enabled, an authenticated user may still exploit an authorization weakness to run code on the registry server.
That creates four material business risks:
This is not solely an information technology concern. You should treat the affected feature-store environment as part of your production data and application estate, with accountable ownership, access controls, monitoring, and tested incident response procedures.
A regional bank: A regional bank uses machine learning features to support fraud scoring and customer-risk analysis. If an attacker compromises the Feast feature-serving environment, they could disrupt data supplied to fraud models or access connected systems and sensitive data, forcing the bank to investigate transaction integrity, customer notification obligations, and service continuity.
A mid-sized retailer: A retailer uses Feast to deliver features for product recommendations, inventory planning, and pricing analytics. An incident could interrupt recommendation services during a high-volume sales period, reduce conversion performance, and create unplanned work for data, platform, security, and customer-support teams.
A healthcare technology provider: A healthcare technology provider runs shared AI infrastructure for several internal products. A compromise in one Feast project could expose weaknesses in tenant separation, creating risk that data or workloads associated with other internal teams become reachable. The resulting investigation may involve contractual requirements, privacy assessments, and validation that affected analytics outputs were not manipulated.
A software-as-a-service company: A growing software-as-a-service provider allows multiple engineering teams to publish machine learning features. If registry write permissions are too broad, a compromised developer account could become a more serious platform incident, potentially enabling unauthorized activity under a service account and allowing movement to connected cloud resources.
CVE-2026-18948 is a reminder that AI infrastructure requires the same disciplined security validation as your customer-facing applications and core cloud services. IntegSec can help you identify exposed Feast services, validate access-control boundaries, test realistic attack paths, and prioritize remediation based on your business risk. A focused penetration test can reveal whether a configuration weakness becomes a practical route to data exposure or platform compromise. Contact IntegSec to strengthen your AI environment and reduce cybersecurity risk with evidence-based testing.
CVE-2026-18948 is an unsafe deserialization flaw in Feast’s handling of registry-stored Python user-defined functions. Feast serializes user-defined functions with the dill library and consumers deserialize the stored function bodies with dill.loads(). Because dill extends Python pickle semantics, deserializing attacker-controlled content can invoke attacker-controlled behavior, including through Python’s __reduce__ mechanism.
The affected code paths include transformations associated with pandas, Python, Substrait, Ray, stream feature views, and profiling functionality. Red Hat describes two primary paths: unauthenticated remote code execution on the feature-server pod under default configurations, and code execution on the registry-server pod by an authenticated principal when deserialization occurs before authorization enforcement.
The assigned CVSS v3.1 vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, corresponding to network reachability, low attack complexity, low privileges, no user interaction, changed scope, and high confidentiality, integrity, and availability impacts. The NVD references CWE-502, Deserialization of Untrusted Data.
Package and deployment enumeration: Engineers should inventory Feast deployments, associated feature-server and registry-server workloads, and Red Hat OpenShift AI installations. In Kubernetes and OpenShift environments, begin with commands such as:
Configuration review: Verify the effective Feast configuration, including whether auth.type: kubernetes is enforced and whether registry writes are denied by default. Review deployment manifests, ConfigMaps, Helm values, and operator-generated resources rather than relying only on repository defaults. Red Hat specifically recommends Kubernetes authentication and deny-by-default registry writes as mitigation.
Log indicators: Review feature-server and registry-server logs for unexpected registry updates, unusual user-defined function processing, failed authorization events near registry changes, and unexpected process execution or outbound connections from service pods.
Behavioral anomalies: Investigators should prioritize sudden workload restarts, unknown processes in Feast containers, new Kubernetes API activity from Feast service accounts, unusual secret access, or unexpected network connections from feature-serving infrastructure.
Network indicators: Monitor ingress requests and internal traffic to Feast application programming interfaces for unexpected registry-write operations, unusually large serialized payloads, or calls from unfamiliar identities. Correlate these events with subsequent feature-server refreshes or online-feature requests.
auth.type: kubernetes through the operator-generated Feast configuration and deny registry writes by default, as recommended by Red Hat. Limit registry-write permissions to narrowly scoped, trusted deployment identities. Remove broad developer, service-account, and pipeline permissions; verify that registry operations are logged; and segment feature-store workloads from sensitive data stores and cloud control-plane services.dill objects. Ensure authorization checks occur before processing untrusted registry content, and establish a secure review process for feature definitions and transformation code.dill, pickle-compatible libraries, or similar mechanisms in production control paths.