
Feast, the feature store half your AI stack runs on, never checked JWT signatures. CVE-2026-92787: forge a token with a hardcoded claim and boom, trusted internal identity. Full read/write on every feature, every model input, every permission policy. Everyone's racing to ship AI features. Nobody checked if the front door even locks.

