CVE-2026-49869

CRITICAL

Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-49869. PoCs published by Ap0dexMe0.

AI-analyzed exploit summary This repository contains a scanner for CVE-2026-49869, which targets an authentication bypass vulnerability in Kestra leading to unauthenticated RCE. The tool performs version detection, probes for bypass paths, and can verify RCE/SSRF chains but does not include a standalone exploit.

Description

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather than an exact path match, any API path whose last segment is configs bypasses authentication entirely. An unauthenticated remote attacker can exploit this to create and execute arbitrary workflows without credentials. Because Kestra ships with script execution plugins (plugin-script-shell, plugin-script-python, etc.) enabled by default, this directly results in unauthenticated Remote Code Execution as root inside the Kestra worker container. This vulnerability is fixed in 1.0.45 and 1.3.21.

Exploits (1)

github SCANNER
by Ap0dexMe0 · pythonpoc
https://github.com/Ap0dexMe0/CVE-2026-49869

This repository contains a scanner for CVE-2026-49869, which targets an authentication bypass vulnerability in Kestra leading to unauthenticated RCE. The tool performs version detection, probes for bypass paths, and can verify RCE/SSRF chains but does not include a standalone exploit.

Classification
Scanner 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Kestra (<= 1.3.20)
No auth needed
Prerequisites: network access to target · Kestra instance running an affected version
mistral-large-3 · analyzed Jun 30, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 10.0
EPSS 0.0089
EPSS Percentile 55.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-184 CWE-287 CWE-78 CWE-918
Status published
Products (3)
kestra/kestra < 1.0.45
kestra-io/kestra < 1.0.45
kestra-io/kestra >= 1.1.0, < 1.3.21
Published Jun 26, 2026
Tracked Since Jun 27, 2026