VYPR
High severity7.5NVD Advisory· Published Mar 20, 2026· Updated Jul 15, 2026

CVE-2026-23536

CVE-2026-23536

Description

A security issue was discovered in the Feast Feature Server's /read-document endpoint that allows an unauthenticated remote attacker to read any file accessible to the server process. By sending a specially crafted HTTP POST request, an attacker can bypass intended access restrictions to potentially retrieve sensitive system files, application configurations, and credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Red Hat/Red Hat OpenShift AI (RHOAI)v5
    cpe:/a:redhat:openshift_ai
  • Feast Dev/Feastllm-fuzzy

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.