CVE-2026-55069
HIGHKestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack
Title source: cnaDescription
Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth authentication component of the Kestra OSS workflow orchestration platform. An attacker who gains read access to the PostgreSQL database can exploit SHA-512's high computation speed to recover the administrator password offline. In Kubernetes deployments, a successful crack further enables reading of the cluster ServiceAccount Token and all K8s Secrets, achieving vertical privilege escalation. This vulnerability is fixed in 1.3.24.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/kestra-io/kestra/security/advisories/GHSA-m727-pcjm-j28h
Scores
CVSS v3
8.7
EPSS
0.0019
EPSS Percentile
9.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-916
Status
published
Products (2)
kestra/kestra
< 1.3.24
kestra-io/kestra
< 1.3.24
Published
Jun 26, 2026
Tracked Since
Jun 27, 2026