chiprook
← Security
SecuritySeptember 21, 2026, 10:20

Suffix Matching Is Not Authorization: Lessons from CVE-2026-49869 in Kestra

Kestra vulnerability CVE-2026-49869 with CVSS 10.0 allowed authentication bypass and OS command execution because path suffix was checked instead of route. Added to CISA KEV catalog on September 2, 2026; fixed in versions 1.0.45 and 1.3.21.

Suffix Matching Is Not Authorization: Lessons from CVE-2026-49869 in Kestra
#Kestra#CISA
Read next
Security

Iranian hackers suspected in attack on Hyundai Glovis tanker off Texas

Security

Cyberattacks Hit OT Systems at Two Colorado Water Utilities

Security

Siemba brings continuous IDOR testing to production APIs

Security

CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog