Kestra CVE-2026-49869: auth bypass via /configs suffix
Kestra OSS patched CVE-2026-49869, where an authentication filter skipped Basic Auth for any path ending in /configs, letting attackers create and run workflows without credentials. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2 September 2026 with a three-day federal remediation deadline.
- AuthenticationFilter used endsWith("/configs") instead of exact path matching
- Unauthenticated attackers can create and execute shell, Python and Node.js tasks
- Fixed in 1.0.45 and 1.3.21; affected: below 1.0.45 and 1.1.0 to below 1.3.21
- CISA added the CVE to KEV on 2 September 2026 with a 3-day deadline
Read next
Security