← back
CVE-2026-49869criticalunder attackCWE-184CWE-287CWE-78CWE-918

Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`

78Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 10epss 2.1%
from disclosure to weapon4 days
Published on NVDJun 26
1st PoC+4d
CISA KEV+68d
exploitation probability
2.1%top 19% of all CVEs
observed exploitation
yesCISA + VulnCheck
3 public exploit(s)
Action required by CISAfederal deadline: 2026-09-05

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

In short

Kestra's authentication check uses a flawed suffix matching that allows attackers to bypass login by accessing API paths ending with 'configs'. This lets anyone create and run malicious workflows that execute code with root privileges on the server.

Technical detail

CVE-2026-49869 exploits improper path validation in AuthenticationFilter (CWE-184, CWE-287) where endsWith("/configs") suffix matching instead of exact path matching allows unauthenticated API access. Remote attackers can bypass authentication and invoke arbitrary workflow execution endpoints, achieving CWE-78 OS command injection and CWE-918 server-side request forgery through default-enabled script execution plugins (shell, Python) running as root in the worker container.

Summary generated and translated by AI from the official description.
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather than an exact path match, any API path whose last segment is configs bypasses authentication entirely. An unauthenticated remote attacker can exploit this to create and execute arbitrary workflows without credentials. Because Kestra ships with script execution plugins (plugin-script-shell, plugin-script-python, etc.) enabled by default, this directly results in unauthenticated Remote Code Execution as root inside the Kestra worker container. This vulnerability is fixed in 1.0.45 and 1.3.21.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
kestra-io · kestra
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.