External risk intelligence

Feast Authentication Bypass Via Unverified JWT Tokens

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-92787

Feast is a feature store platform typically deployed within internal data science and machine learning infrastructure to manage data pipelines. While it may provide APIs for model serving, it is generally not designed as a public-facing internet service, though some deployments may be exposed to the wider internal network or edge environments depending on the organization's architecture.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability allows unauthorized access to sensitive data and system controls within the Feast platform by bypassing authentication mechanisms. An attacker could exploit this to gain unchecked read and write access to all managed data and configurations.

  • Unverified tokens grant full system access.
  • Critical data and controls are exposed to attackers.
  • Confirm relevance and potential exposure to your environment.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted, unverified JWT to the Feast server. This bypasses the signature check, allowing the attacker to impersonate a legitimate user and gain unauthorized access to all data and configurations.

  • Network access required.
  • Unverified JWT token presented.
  • Full data and configuration access.

Live Threat

Current exploitation, exposure, and threat context

A critical vulnerability in Feast allows unauthenticated attackers to bypass access controls by submitting an unverified JWT. This could grant them unchecked read and write access to sensitive system data, including feature views, data sources, and permission policies on the server.

  • Sensitive system data at risk.
  • Unverified tokens bypass authentication.
  • Unchecked access to all entities.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Feast and associated platform teams are most likely responsible for addressing this authentication bypass vulnerability. The immediate first step is to identify all instances of the affected technology, confirm their exposure and business criticality, and assign an accountable owner to develop a targeted remediation plan.

  • Platform and application owners
  • Confirm token verification and server reachability
  • Plan remediation based on exposure and criticality

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Feast and why is it used?

Feast is an open-source feature store platform designed for machine learning teams. It manages the lifecycle of data features—the inputs used to train models—ensuring they are consistent across both training and real-time production environments. By acting as a centralized repository for data pipelines, it allows organizations to share, discover, and serve data features efficiently within their data science infrastructure.

What does CVE-2026-92787 mean for Feast security?

This vulnerability is classified as Use of Hardcoded Credentials (CWE-798). Specifically, the software fails to verify the digital signatures on JWT tokens used for identity. Because the system trusts unverified tokens that contain hardcoded claim values, it incorrectly authenticates unauthorized users, effectively granting them full administrative control over the server and all hosted data.

How does an attacker trigger this vulnerability?

An attacker triggers the bug by sending a network request to the Feast server containing a malformed or forged JWT. Because the server skips the required cryptographic signature verification process, the attacker does not need a valid password or token from a legitimate user. Simply presenting an unverified token with the expected hardcoded claim value is sufficient to bypass all role-based access controls.

Do I need to worry if my Feast instance is internal?

According to Halo Surface Signal, Feast is typically deployed within internal machine learning infrastructure rather than as a public-facing service. However, you should still evaluate your specific setup, as some deployments may be reachable from wider internal networks or edge environments, potentially increasing the risk if an attacker has already gained a foothold elsewhere in your organization.

What is the first step to address this issue?

Begin by creating an inventory of all Feast instances currently running in your environment to understand your total footprint. Once identified, prioritize these instances based on their business criticality and network connectivity. Assign an owner for each instance to confirm whether token verification is active and to establish a remediation plan to secure these authentication pathways.

References