CVE-2026-49869
Published Jun 26, 2026
Last updated 2 days ago
- Description
- Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather than an exact path match, any API path whose last segment is configs bypasses authentication entirely. An unauthenticated remote attacker can exploit this to create and execute arbitrary workflows without credentials. Because Kestra ships with script execution plugins (plugin-script-shell, plugin-script-python, etc.) enabled by default, this directly results in unauthenticated Remote Code Execution as root inside the Kestra worker container. This vulnerability is fixed in 1.0.45 and 1.3.21.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- kestra
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Kestra OSS OS Command Injection Vulnerability
- Exploit added on
- Sep 2, 2026
- Exploit action due
- Sep 5, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- security-advisories@github.com
- CWE-78
- Hype score
- Not currently trending
🚨 Alerte CISA : CVE-2026-49869, RCE critique non authentifiée dans Kestra OSS activement exploitée depuis fin juin 2026 pour des reverse shells. #zoneantimalware https://t.co/fqbcY4WMZO
@NicolasCoolman
4 Sept 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISAが既知の悪用された脆弱性7件をカタログに追加 #CISA (Sep 2) CVE-2026-9586 Sangoma SwitchvoxのSQLインジェクション脆弱性 CVE-2026-48710 Kludex Starlette HTTPリクエスト/レスポンスの密輸脆弱性 CVE-2026-49869 Kestra OSS OSのコマ
@foxbook
3 Sept 2026
263 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-49869: Kestra OSS Unauthenticated OS Command Injection Actively Exploi… "On September 2, 2026, CISA added CVE-2026-49869 to the Known Exploited…" 🔗 https://t.co/al0CvmT11q #CyberSecurity #ThreatIntel #cve202649869 #critical #cisakev
@SecurityAr58409
3 Sept 2026
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-49869: #Kestra Multi-CVE #Exploit Kit Multi-exploits kit for Kestra workflow orchestration platform vulnerabilities. CVEs Covered | CVE | CVSS | Description | |-----|------|-------------| | CVE-2026-49869 | 9.8 | Unauthenticated RCE via AuthenticationFilter bypass…
@lyrie_ai
21 Jul 2026
39 Impressions
0 Retweets
1 Like
0 Bookmarks
2 Replies
0 Quotes
#Kestra Multi-CVE #Exploit Kit Multi-exploits kit for Kestra workflow orchestration platform vulnerabilities. CVEs Covered | CVE | CVSS | Description | |-----|------|-------------| | CVE-2026-49869 | 9.8 | Unauthenticated RCE via AuthenticationFilter bypass | | CVE-2026-53576
@YogSoth0
30 Jun 2026
1264 Impressions
0 Retweets
22 Likes
8 Bookmarks
0 Replies
0 Quotes
🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-49869](https://t.co/y6fkLlCTKS) Kes... https://t.co/y6fkLlCTKS #ZeroDay #PatchManagement #Vulnerability
@MalwareObserver
26 Jun 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2026-49869 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/config… https://t.co/lP8hEpetRm ----- Traducción: CVE-2026-49869 Kes… https://t.co/utmtNg
@infoflowcloud
26 Jun 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:kestra:kestra:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ADC0ED79-69EF-4A2A-9F07-4791ED97124F",
"versionEndExcluding": "1.0.45",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:kestra:kestra:*:*:*:*:*:*:*:*",
"matchCriteriaId": "73FD0092-9076-4F1C-9B93-E59C09D30E21",
"versionEndExcluding": "1.3.21",
"versionStartIncluding": "1.1.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]