Event-Driven Orchestration Platform Vulnerability in Kestra by Kestra-IO
CVE-2026-73245
6.5MEDIUM
What is CVE-2026-73245?
Kestra, an open-source event-driven orchestration platform, presents a security issue prior to version 2.0.0-rc6. The platform’s configuration file exposes Micronaut management endpoints on port 8081 without authentication. This lack of security allows attackers to make unauthenticated GET requests to /env, potentially disclosing sensitive configuration details, and to leverage POST requests on /loggers/{name} to manipulate runtime log levels. This issue has been addressed in version 2.0.0-rc6.
Affected Version(s)
kestra < 2.0.0-rc6
