CVE-2026-49869
CRITICALKestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-49869. PoCs published by Ap0dexMe0.
AI-analyzed exploit summary This repository contains a scanner for CVE-2026-49869, which targets an authentication bypass vulnerability in Kestra leading to unauthenticated RCE. The tool performs version detection, probes for bypass paths, and can verify RCE/SSRF chains but does not include a standalone exploit.
Description
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather than an exact path match, any API path whose last segment is configs bypasses authentication entirely. An unauthenticated remote attacker can exploit this to create and execute arbitrary workflows without credentials. Because Kestra ships with script execution plugins (plugin-script-shell, plugin-script-python, etc.) enabled by default, this directly results in unauthenticated Remote Code Execution as root inside the Kestra worker container. This vulnerability is fixed in 1.0.45 and 1.3.21.
Exploits (1)
This repository contains a scanner for CVE-2026-49869, which targets an authentication bypass vulnerability in Kestra leading to unauthenticated RCE. The tool performs version detection, probes for bypass paths, and can verify RCE/SSRF chains but does not include a standalone exploit.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H