← Browse

CVE-2026-49869

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
1.9%
78.9th percentile
CISA KEV
Listed
Added 2026-09-02 · patch by 2026-09-05
Weakness / dates
CWE-78
Published 2026-06-26 · modified 2026-09-03

Description

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather than an exact path match, any API path whose last segment is configs bypasses authentication entirely. An unauthenticated remote attacker can exploit this to create and execute arbitrary workflows without credentials. Because Kestra ships with script execution plugins (plugin-script-shell, plugin-script-python, etc.) enabled by default, this directly results in unauthenticated Remote Code Execution as root inside the Kestra worker container. This vulnerability is fixed in 1.0.45 and 1.3.21.

Affected

kestra

References

Official: NVD · CVE.org