THREAT OPS › Threat News › [NVD] CVE-2026-92787 (CRITICAL 9.8) — Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecke
[NVD] CVE-2026-92787 (CRITICAL 9.8) — Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecke
CVE-2026-92787 CVSS: 9.8 CRITICAL Published: 2026-09-16T21:17:28.023
Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature v
Indicators of compromise
- CVE-2026-92787cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-92787