Event-Driven Orchestration Platform Vulnerability in Kestra by Kestra-IO
CVE-2026-73245

6.5MEDIUM

Key Information:

Vendor

Kestra-io

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73245?

Kestra, an open-source event-driven orchestration platform, presents a security issue prior to version 2.0.0-rc6. The platform’s configuration file exposes Micronaut management endpoints on port 8081 without authentication. This lack of security allows attackers to make unauthenticated GET requests to /env, potentially disclosing sensitive configuration details, and to leverage POST requests on /loggers/{name} to manipulate runtime log levels. This issue has been addressed in version 2.0.0-rc6.

Affected Version(s)

kestra < 2.0.0-rc6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.