CVE-2026-14621 | FederatedAI FATE up to 2.2.0 OSX Broker QueuePushReqStreamObserver.java QueuePushReqStreamObserver.initEggroll rollSiteSessionId/dstRole/dstPartyId wrong session (Issue 5791 / EUVD-2026-41660)
A vulnerability described as problematic has been identified in FederatedAI FATE up to 2.2.0. This affects the function QueuePushReqStreamObserver.initEggroll of the file java/osx/osx-broker/src/main/java/org/fedai/osx/broker/grpc/QueuePushReqStreamObserver.java of the component OSX Broker. Such manipulation of the argument rollSiteSessionId/dstRole/dstPartyId leads to exposure of data element to wrong session.
This vulnerability is documented as CVE-2026-14621. The attack can be executed remotely. Additionally, an exploit exists.
The pull request to fix this issue awaits acceptance.