CVE-2026-23536 carries a CVSS 3.1 base score of 7.5 against the Feast Feature Server component shipped with Red Hat OpenShift AI (RHOAI). NVD classifies it under CWE-22 (Path Traversal). VulnCheck’s KEV feed reports the CVE as exploited, dated September 14, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-23536 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description states the Feast Feature Server’s /read-document endpoint allows an unauthenticated remote attacker to read any file accessible to the server process. NVD states an attacker can send a specially crafted HTTP POST request to bypass the endpoint’s intended access restrictions and retrieve sensitive system files, application configurations, and credentials.
Evidence and confidence
- Medium confidence — the CVSS 7.5 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), the CWE-22 classification, and the affected endpoint all trace to NVD alone in our current ingestion. The exploitation report traces to VulnCheck KEV alone. - High exploitation probability — FIRST’s EPSS model scores this CVE at 0.01912, a 78.8th percentile score as of our ingestion — notably high for a VulnCheck-only listing.
No field is in conflict between our two sources. Our source data does not carry a fixed-version field; consult Red Hat’s own security advisory directly for patch guidance.
Why this matters
Feature servers like Feast sit inside MLOps pipelines specifically to serve model-training and inference data, which frequently includes proprietary datasets, connection strings to upstream data stores, and service credentials — exactly the kind of material an unauthenticated file-read primitive can expose. Red Hat OpenShift AI deployments are enterprise machine-learning platforms that may hold sensitive training data across multiple projects, making this a meaningful data-exposure risk anywhere the Feast Feature Server component is internet-facing or reachable from an untrusted network segment.
Frequently Asked Questions
What is CVE-2026-23536?
A CVSS 7.5 path traversal vulnerability (CWE-22) in the Feast Feature Server’s /read-document endpoint, shipped as part of Red Hat OpenShift AI, allowing unauthenticated attackers to read arbitrary files accessible to the server process.
Is CVE-2026-23536 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 14, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Do I need an account to exploit this? No. NVD’s description confirms this is exploitable by an unauthenticated remote attacker via a crafted HTTP POST request.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which version fixes this? Our source data does not carry a specific fixed-version field. Consult Red Hat’s own security advisory for the patched OpenShift AI release.
Severity, vector, weakness classification, and the described mechanism sourced from the National Vulnerability Database record for CVE-2026-23536. Red Hat’s own advisory: Red Hat CVE page for CVE-2026-23536. Exploitation status and the September 14, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.