Suffix Matching Is Not Authorization: Lessons from CVE-2026-49869 in Kestra
Kestra vulnerability CVE-2026-49869 with CVSS 10.0 allowed authentication bypass and OS command execution because path suffix was checked instead of route. Added to CISA KEV catalog on September 2, 2026; fixed in versions 1.0.45 and 1.3.21.
- CVSS 10.0, added to CISA KEV catalog on September 2, 2026
- Bypass via flow name configs led to shell command execution in container
- Fixed in Kestra 1.0.45 and 1.3.21 and later
- API ports 8080 and 8006 should not be exposed to internet
Read next
Security