---
id: CVE-2026-14621
title: A vulnerability has been found in FederatedAI FATE up to 2.2.0
summary: >-
  A vulnerability has been found in FederatedAI FATE up to 2.2.0. This affects
  the function QueuePushReqStreamObserver.initEggroll of the file
  java/osx/osx-broker/src/main/java/org/fedai/osx/broker/grpc/QueuePushReqStreamObserver.java
  of t…
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-488
published: '2026-07-04'
updated: '2026-07-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14621'
references:
  - url: 'https://github.com/FederatedAI/FATE/'
    label: cna@vuldb.com
  - url: 'https://github.com/FederatedAI/FATE/issues/5791'
    label: cna@vuldb.com
  - url: 'https://github.com/FederatedAI/FATE/pull/5792'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-14621'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/844900'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/376137'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/376137/cti'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00365
epssPercentile: 0.27701
ingestedAt: '2026-07-04T21:57:46.872Z'
---

## Overview

A vulnerability has been found in FederatedAI FATE up to 2.2.0. This affects the function QueuePushReqStreamObserver.initEggroll of the file java/osx/osx-broker/src/main/java/org/fedai/osx/broker/grpc/QueuePushReqStreamObserver.java of the component OSX Broker. Such manipulation of the argument rollSiteSessionId/dstRole/dstPartyId leads to exposure of data element to wrong session. The attack can be executed remotely. A high complexity level is associated with this attack. It is indicated that the exploitability is difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
