Kestra Authentication Bypass Bug Actively Exploited, CISA Adds to KEV Catalog
A critical OS command injection vulnerability in Kestra, an event-driven workflow orchestration platform, has been added to CISA's Known Exploited Vulnerabilities catalog following evidence of real-world attacks. Tracked as CVE-2026-49869 and rated 10.0 in severity, the flaw stems from an authentication filter that matched request paths by suffix rather than exact route, allowing unauthenticated users to create and execute arbitrary workflows. Kestra released patches in versions 1.0.45 and 1.3.21 on June 2–3, 2026, but CISA's KEV listing only came on September 2, 2026 — three months later. The delay highlights a common gap where a patch exists but risk persists due to incomplete asset inventories, unrebult containers, or undetected prior compromise. Organizations running affected versions are urged to update immediately, audit workflow definitions for unauthorized entries, and review execution and network logs for signs of exploitation.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in