CVE-2026-23536

A security issue was discovered in the Feast Feature Server's `/read-document` endpoint that allows an unauthenticated remote attacker to read any file accessible to the server process. By sending a specially crafted HTTP POST request, an attacker can bypass intended access restrictions to potentially retrieve sensitive system files, application configurations, and credentials.
Configurations

No configuration.

History

30 Jun 2026, 03:17

Type Values Removed Values Added
References
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23536.json -
References () https://access.redhat.com/security/cve/CVE-2026-23536 - () https://access.redhat.com/security/cve/CVE-2026-23536 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=2429302 - () https://bugzilla.redhat.com/show_bug.cgi?id=2429302 -

17 Jun 2026, 10:21

Type Values Removed Values Added
Summary
  • (es) Se descubrió una vulnerabilidad de seguridad en el endpoint '/read-document' del Feast Feature Server que permite a un atacante remoto no autenticado leer cualquier archivo accesible para el proceso del servidor. Al enviar una solicitud HTTP POST especialmente diseñada, un atacante puede eludir las restricciones de acceso previstas para recuperar potencialmente archivos de sistema sensibles, configuraciones de aplicaciones y credenciales.

20 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 22:16

Updated : 2026-07-15 02:18


NVD link : CVE-2026-23536

Mitre link : CVE-2026-23536

CVE.ORG link : CVE-2026-23536


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')