Unauthenticated Remote Code Execution in Kestra Orchestration Platform
CVE-2026-49869

10CRITICAL

Key Information:

Vendor

Kestra-io

Status
Vendor
CVE Published:
26 June 2026

Badges

📈 Score: 233👾 Exploit Exists🟡 Public PoC🦅 CISA Reported

What is CVE-2026-49869?

CVE-2026-49869 is a critical vulnerability found in the Kestra orchestration platform, an open-source solution designed for event-driven workflow management. This vulnerability arises due to a flaw in the AuthenticationFilter component within Kestra OSS, where the method for determining access to the public configuration endpoint is based on a suffix match instead of an exact path match. This oversight allows any API path ending in "configs" to bypass authentication entirely. As a result, an unauthenticated attacker can exploit this vulnerability to create and execute arbitrary workflows without requiring any credentials. The ability to execute scripts with root privileges within the Kestra worker container poses a severe risk, potentially allowing attackers to gain full control of the affected systems. This vulnerability affects versions prior to 1.0.45 and 1.3.21, and corrective measures have been implemented in these subsequent releases.

Potential impact of CVE-2026-49869

  1. Unauthenticated Remote Code Execution: This vulnerability allows attackers to perform remote code execution without authentication, enabling them to deploy malicious scripts and workflows within the Kestra environment, which can lead to extensive system compromise.

  2. Escalation of Privileges: The ability to execute code as root in the worker container significantly increases the stakes of the attack, allowing an unauthorized user to manipulate system processes and access sensitive information.

  3. Risk of Data Breaches and System Integrity Loss: Exploiting this vulnerability could lead to unauthorized access to system data, compromising data integrity and confidentiality. This poses a substantial risk for organizations relying on the Kestra platform for critical operations.

CISA has reported CVE-2026-49869

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-49869 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

kestra < 1.0.45 < 1.0.45

kestra >= 1.1.0, < 1.3.21 < 1.1.0, 1.3.21

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • Vulnerability published

  • Vulnerability Reserved

.