Finding the Workflow Orchestrators: ZoomEye Exposure Data for Kestra After CVE-2026-49869
A critical vulnerability CVE-2026-49869 (CVSS 10.0) was found in Kestra OSS — authentication bypass via paths ending in /configs, escalating to remote code execution. The vulnerability was added to CISA's exploited catalog on September 2, 2026; fixes are in versions 1.0.45 and 1.3.21.
- CVSS 3.1 — 10.0, added to CISA's exploited vulnerabilities catalog on September 2, 2026
- Affects Kestra OSS up to and including 1.3.20, fixes in 1.0.45 and 1.3.21
- ZoomEye found 119 assets for app="Kestra" and 231 for title="Kestra"
- Script execution plugins are enabled by default, facilitating RCE
Read next
Security