CVE-2026-49869

Published Jun 26, 2026

Last updated 2 days ago

Exploit knownCVSS critical 10.0
plugin-script-shell
Kestra OSS
Kestra

Overview

Description
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather than an exact path match, any API path whose last segment is configs bypasses authentication entirely. An unauthenticated remote attacker can exploit this to create and execute arbitrary workflows without credentials. Because Kestra ships with script execution plugins (plugin-script-shell, plugin-script-python, etc.) enabled by default, this directly results in unauthenticated Remote Code Execution as root inside the Kestra worker container. This vulnerability is fixed in 1.0.45 and 1.3.21.
Source
security-advisories@github.com
NVD status
Analyzed
Products
kestra

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Kestra OSS OS Command Injection Vulnerability
Exploit added on
Sep 2, 2026
Exploit action due
Sep 5, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

security-advisories@github.com
CWE-78

Social media

Hype score
Not currently trending
  1. 🚨 Alerte CISA : CVE-2026-49869, RCE critique non authentifiée dans Kestra OSS activement exploitée depuis fin juin 2026 pour des reverse shells. #zoneantimalware https://t.co/fqbcY4WMZO

    @NicolasCoolman

    4 Sept 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CISAが既知の悪用された脆弱性7件をカタログに追加 #CISA (Sep 2) CVE-2026-9586 Sangoma SwitchvoxのSQLインジェクション脆弱性 CVE-2026-48710 Kludex Starlette HTTPリクエスト/レスポンスの密輸脆弱性 CVE-2026-49869 Kestra OSS OSのコマ

    @foxbook

    3 Sept 2026

    263 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🔒 #CyberSecurity CVE-2026-49869: Kestra OSS Unauthenticated OS Command Injection Actively Exploi… "On September 2, 2026, CISA added CVE-2026-49869 to the Known Exploited…" 🔗 https://t.co/al0CvmT11q #CyberSecurity #ThreatIntel #cve202649869 #critical #cisakev

    @SecurityAr58409

    3 Sept 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2026-49869: #Kestra Multi-CVE #Exploit Kit Multi-exploits kit for Kestra workflow orchestration platform vulnerabilities. CVEs Covered | CVE | CVSS | Description | |-----|------|-------------| | CVE-2026-49869 | 9.8 | Unauthenticated RCE via AuthenticationFilter bypass…

    @lyrie_ai

    21 Jul 2026

    39 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    2 Replies

    0 Quotes

  5. #Kestra Multi-CVE #Exploit Kit Multi-exploits kit for Kestra workflow orchestration platform vulnerabilities. CVEs Covered | CVE | CVSS | Description | |-----|------|-------------| | CVE-2026-49869 | 9.8 | Unauthenticated RCE via AuthenticationFilter bypass | | CVE-2026-53576

    @YogSoth0

    30 Jun 2026

    1264 Impressions

    0 Retweets

    22 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  6. 🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-49869](https://t.co/y6fkLlCTKS) Kes... https://t.co/y6fkLlCTKS #ZeroDay #PatchManagement #Vulnerability

    @MalwareObserver

    26 Jun 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨*CVE* CVE-2026-49869 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/config… https://t.co/lP8hEpetRm ----- Traducción: CVE-2026-49869 Kes… https://t.co/utmtNg

    @infoflowcloud

    26 Jun 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations