THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-92787 (CRITICAL 9.8) — Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecke

[NVD] CVE-2026-92787 (CRITICAL 9.8) — Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecke

mednvdPublished 2026-09-16

CVE-2026-92787 CVSS: 9.8 CRITICAL Published: 2026-09-16T21:17:28.023

Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature v

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-92787