Vulnerability
Published 2026-09-02
Verified 2026-09-19

Kestra OSS auth bypass via /configs suffix (CVE-2026-49869) → unauth RCE; CISA KEV

Kestra GHSA-5vc5-wxxq-3fjx (CVE-2026-49869) is Critical: AuthenticationFilter whitelists any path whose last segment is configs via endsWith("/configs"), so unauthenticated callers can hit flow/execution APIs and, with default script plugins, achieve remote code execution as root in the worker container. GHSA CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (10.0). Affected through 1.3.20; patched in 1.0.45 and 1.3.21. CISA added it to KEV on 2 September 2026. Upgrade Kestra OSS immediately; do not expose the webserver to untrusted networks until patched.

Product
Kestra OSS
Versions
Affected through 1.3.20; fixed in 1.0.45 and 1.3.21
CVSS
(CVSS 3.1 Critical, GHSA vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploited in Australia?
unknown
Patch to
Kestra 1.3.21 or 1.0.45 (or later); restrict webserver exposure

Primary: GitHub GHSA-5vc5-wxxq-3fjx (Kestra) · Vendor: Kestra (vendor advisory) · CVE: CVE-2026-49869 · CISA KEV alert (2 Sep 2026)

vulnerabilities cloud ai