Kestra auth bypass lets attackers run root workflows
Kestra advisory GHSA-5vc5-wxxq-3fjx assigns CVE-2026-49869, a CVSS 10.0 auth bypass via a /configs suffix match. CISA added it to KEV on 2 September 2026 with a 5 September BOD 26-04 due date and forensic triage required. Patch to 1.0.45 or 1.3.21.

Kestra published GitHub Security Advisory GHSA-5vc5-wxxq-3fjx for CVE-2026-49869. The advisory rates it Critical at CVSS 3.1 10.0. The bug is an authentication bypass in AuthenticationFilter: the public config endpoint is whitelisted with a suffix match on paths that end in /configs, so any API path whose last segment is configs skips Basic Auth.
An unauthenticated caller who can reach the API can create and execute workflows. Default script plugins (shell, python, node, bash, and more than 80 others) then run as root inside the worker container. The advisory says Kestra OSS with default Basic Auth is in scope, and network access to the API port is enough even if the instance is not on the public internet.
This is a vendor GitHub Security Advisory that assigns the CVE, plus a CISA Known Exploited Vulnerabilities catalog listing. It is not a ransomware attribution. CISA records ransomware use as Unknown.
CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2 September 2026, in a seven-CVE batch that also included the JFrog Artifactory auth bypass and the SonicWall SMA 1000 pair. The federal BOD 26-04 due date was 5 September 2026, already passed, and the catalog row requires forensic triage.
The same advisory documents a second path: Pebble's http() function has no URI filtering, so the bypass can also reach cloud metadata at 169.254.169.254. Fixes are 1.0.45 and 1.3.21 on the respective branches. Versions through 1.3.20 on the 1.3 line are called out as affected.
CISA listed the bug because it has evidence of exploitation. That is not a named-group attribution. The advisory also limits the RCE: root inside the worker container, with no confirmed Docker-socket escape.
Unauthenticated execution on a reachable API is the same class of event as StyleSmuggler on Magento and Adobe Commerce. Earlier ownCloud and Artifactory KEV rows already showed how fast a catalog due date arrives.
If you run Kestra OSS, upgrade to 1.0.45 or 1.3.21 immediately, then open forensic triage on any instance that was reachable before 5 September. Hunt for unexpected workflows or executions named configs, and do not treat a clean upgrade as proof the box was quiet.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free