CVE-2026-92787

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 2 mentions (2026-09-17); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-09-17: 2Mentions · 2026-09-18: 109-1709-18
Referenced assets2 URLs
Full discourse3 posts
  • Daniel Púa@devploit

    Feast, the feature store half your AI stack runs on, never checked JWT signatures. CVE-2026-92787: forge a token with a hardcoded claim and boom, trusted internal identity. Full read/write on every feature, every model input, every permission policy. Everyone's racing to ship AI features. Nobody checked if the front door even locks.

    10022189
    3.1K followersView on X
  • Severity Daily@severitydaily

    Feast's Helm chart hardcodes the one value that lets an unsigned JWT skip all access control, so every default install shares it. No fixed release — 0.66.0 is still the newest. No exploitation reported. https://severitydaily.com/feast-cve-2026-92787-helm-chart-intra-communication-constant-rbac-bypass/

    0000020
    24 followersView on X
  • Daniel Púa@devploit

    https://nvd.nist.gov/vuln/detail/cve-2026-92787

    0000081
    3.1K followersView on X

Explore more