Skip to main content
QUIETLYTIC
Vulnerability

Kestra OSS Authentication Bypass (CVE-2026-49869)

CVE-2026-49869 is a CVSS 10.0 authentication-filter bypass in Kestra OSS, KEV-listed Sept. 2, 2026 as exploited. NVD reports fixes in 1.0.45 and 1.3.21.

CVE-2026-49869
Threat Level
CRITICAL
CVSS
10.0
Status
Active Exploitation
Confidence
High
Affected Products
Kestra OSS

CVE-2026-49869 is a CVSS 3.1 base 10.0 flaw in Kestra OSS that CISA added to the Known Exploited Vulnerabilities catalog on September 2, 2026. NVD published the record on June 26, 2026 — roughly two months before the KEV listing — and reports the issue fixed in Kestra 1.0.45 and 1.3.21.

The root cause is a string comparison

Per NVD’s description, Kestra’s AuthenticationFilter exempts the public configuration endpoint from Basic Auth by testing whether the request path ends with /configs rather than testing whether it equals that path. A suffix match is not a path match. NVD states that any API path whose final segment is configs therefore skips authentication entirely.

The consequence NVD describes is not limited to reading configuration. Kestra is a workflow orchestrator, and NVD’s record states that an unauthenticated remote attacker can create and execute arbitrary workflows without credentials. Because Kestra ships script-execution plugins such as plugin-script-shell and plugin-script-python enabled by default, NVD characterises the end result as unauthenticated remote code execution as root inside the Kestra worker container.

That chain — an authentication-filter shortcut, an orchestration engine whose whole job is running submitted code, and a default plugin set that makes shell execution a first-class feature — is why a one-line comparison bug carries a 10.0.

Severity, exploitation and confidence are three different things

NVD scores CVE-2026-49869 CVSS 3.1 base 10.0 (critical), vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. That score, the vector, and the flaw description are single-sourced to NVD in our source data — medium confidence, not because we doubt them, but because nothing else in our ingested data independently restates them.

The exploitation claim stands on firmer ground. CISA KEV and VulnCheck KEV both record the vulnerability as known-exploited with an added date of September 2, 2026, and both carry the same CISA title, “Kestra OSS OS Command Injection Vulnerability.” VulnCheck additionally classifies exploit availability as active. CISA does not list a CVE on speculation, so exploitation status here is high confidence.

Note the classification tension worth reading carefully: CISA’s KEV title names this an OS command injection, while the underlying NVD description locates the defect in the authentication filter. Both are accurate descriptions of different links in the same chain — the weakness IDs NVD, CISA KEV and VulnCheck KEV all agree on (CWE-78, CWE-184, CWE-287 and CWE-918) span exactly that range, from incomplete denylist and improper authentication through to command injection. We are not reconciling them into one label.

Why this matters for self-hosted infrastructure

Orchestration platforms sit in an awkward place operationally. They are internal tooling, so they rarely get the perimeter scrutiny a VPN appliance gets, and they hold broad credentials by design because their purpose is reaching every system a pipeline touches. A pre-authentication path into one is worth substantially more to an attacker than its network position suggests.

The ten-week gap between NVD’s June 26 publication and the September 2 KEV listing is the operationally relevant number here. A fix existed in 1.0.45 and 1.3.21 well before CISA saw exploitation evidence. Organisations running a self-hosted Kestra instance pinned to an older release had a patch available for the entire interval.

CISA added this alongside the SonicWall SMA1000 pair, CVE-2026-83548 and CVE-2026-83549, on the same September 2 date — different technology, same KEV batch. The closer conceptual neighbour is LiteLLM’s CVE-2026-59822 authentication bypass, which reached KEV one day later, on September 3: another self-hosted open-source service whose authentication layer, rather than its core logic, turned out to be the weak point.

Intelligence gaps

  • No EPSS score. Our pipeline holds no FIRST EPSS score or percentile for CVE-2026-49869. Exploitation is confirmed by KEV listing, but we cannot express a modelled probability.
  • No structured version ranges. The affected and fixed versions above come from NVD’s prose description, not from structured version data. NVD points to the vendor’s GitHub security advisory, GHSA-5vc5-wxxq-3fjx, for authoritative version detail.
  • No per-field source URLs. Our provenance records name the contributing source for each field but hold no per-field link, so we attribute by source name rather than invent a citation URL.
  • No deployment-scale data. We have no basis for estimating how many internet-reachable Kestra instances exist, and we do not guess.

Frequently Asked Questions

What is CVE-2026-49869? An authentication bypass in Kestra OSS caused by an endpoint whitelist that matches on path suffix instead of exact path, which NVD reports leads to unauthenticated remote code execution. NVD scores it CVSS 3.1 base 10.0.

Which Kestra versions are affected? Per NVD’s description, releases prior to 1.0.45 and 1.3.21. Those two releases contain the fix.

Is CVE-2026-49869 actively exploited? Yes. CISA added it to the KEV catalog on September 2, 2026, and VulnCheck’s KEV data records the same status and date.

Why is the CVSS score a full 10.0 rather than 9.8? NVD’s vector includes a scope change (S:C) on top of network reach, no required privileges and no user interaction — impact crosses the security boundary of the vulnerable component, which is what lifts an otherwise-9.8 profile to 10.0.


Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, with corroborating KEV metadata from VulnCheck, aggregated September 17, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools