Critical Kestra Auth Bypass CVE-2026-49869 Leaves Hundreds of Instances Exposed Online
A critical authentication bypass vulnerability, CVE-2026-49869, was discovered in Kestra OSS, affecting versions up to 1.3.20 and receiving a maximum CVSS score of 10.0. The flaw resided in the AuthenticationFilter, where any API request path ending in '/configs' bypassed Basic Authentication, allowing unauthenticated attackers to reach protected endpoints. Because Kestra ships with script execution plugins by default, an anonymous attacker could create and trigger workflows to execute arbitrary commands on the server. ZoomEye scans conducted on September 16, 2026 identified between 119 and 231 publicly exposed Kestra instances, though the figures overlap and do not confirm which versions are running. Kestra has released patched versions 1.0.45 and 1.3.21, and the vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on September 2, 2026.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in