Authentication Vulnerability in Kestra Open-source Orchestration Platform
CVE-2026-55069

8.7HIGH

Key Information:

Vendor

Kestra-io

Status
Vendor
CVE Published:
26 June 2026

What is CVE-2026-55069?

The Kestra OSS workflow orchestration platform contains a vulnerability in its BasicAuth authentication component, allowing an attacker with read access to the PostgreSQL database to exploit the SHA-512 hashing algorithm's computational speed. This can lead to the offline recovery of the administrator password. In Kubernetes environments, a successful attack can also provide access to the cluster's ServiceAccount Token and all K8s Secrets, resulting in significant vertical privilege escalation. This issue has been addressed in version 1.3.24.

Affected Version(s)

kestra < 1.3.24

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.