chiprook
← Security
SecuritySeptember 16, 2026, 11:01

Finding the Workflow Orchestrators: ZoomEye Exposure Data for Kestra After CVE-2026-49869

A critical vulnerability CVE-2026-49869 (CVSS 10.0) was found in Kestra OSS — authentication bypass via paths ending in /configs, escalating to remote code execution. The vulnerability was added to CISA's exploited catalog on September 2, 2026; fixes are in versions 1.0.45 and 1.3.21.

Finding the Workflow Orchestrators: ZoomEye Exposure Data for Kestra After CVE-2026-49869
#Kestra#CISA
Read next
Security

Contagious Interview Campaign Hits 30,000 Devices, Steals $10.71M in Crypto

Security

Google Releases AndroidX Libraries for Granular Android Patch Checks

Security

Surfshark: iPhone lets you delete 98% of preinstalled apps, Google only 38%

Security

Hackers extract 1.6 million images and 27,000 videos from a single Flock camera