Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Kestra's authentication check uses a flawed suffix matching that allows attackers to bypass login by accessing API paths ending with 'configs'. This lets anyone create and run malicious workflows that execute code with root privileges on the server.
CVE-2026-49869 exploits improper path validation in AuthenticationFilter (CWE-184, CWE-287) where endsWith("/configs") suffix matching instead of exact path matching allows unauthenticated API access. Remote attackers can bypass authentication and invoke arbitrary workflow execution endpoints, achieving CWE-78 OS command injection and CWE-918 server-side request forgery through default-enabled script execution plugins (shell, Python) running as root in the worker container.