chiprook
← Security
SecurityOctober 3, 2026, 15:40

Kestra CVE-2026-49869: auth bypass via /configs suffix

Kestra OSS patched CVE-2026-49869, where an authentication filter skipped Basic Auth for any path ending in /configs, letting attackers create and run workflows without credentials. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2 September 2026 with a three-day federal remediation deadline.

Kestra CVE-2026-49869: auth bypass via /configs suffix
#Kestra#CISA
Read next
Security

CISA adds critical Kestra CVE-2026-49869 to KEV catalog

Security

Finding the Workflow Orchestrators: ZoomEye Exposure Data for Kestra After CVE-2026-49869

Security

LiteLLM auth bypass: a one-character token unlocked MCP tools

Security

CISA adds JFrog Artifactory auth bypass to exploited vulnerabilities list