← Back to Research Blog
CRITICAL CVE-2026-49869

Critical Unauthenticated RCE Vulnerability in Kestra Orchestration Platform

10.0
CRITICAL
kestra, plugin-script-python, plugin-scr
2026-08-11

Overview

CVE-2026-49869 exposes Kestra users to unauthenticated remote code execution with root privileges due to a flawed authentication bypass in the /configs endpoint. This critical vulnerability affects default installations with script execution plugins enabled.


Technical Analysis

The AuthenticationFilter's use of a suffix match (request.getPath().endsWith("/configs")) instead of an exact path check allows attackers to craft arbitrary API paths ending in 'configs'. This bypasses authentication entirely, enabling workflow creation and execution through default plugins like plugin-script-shell and plugin-script-python. Exploitation requires no credentials and directly achieves container-level code execution as root.

Enterprise & DIB Impact

Defense industrial base and enterprise environments using Kestra for workflow automation face immediate risk of system compromise, data exfiltration, and operational disruption. Attackers can leverage this vulnerability to establish persistent access without requiring any user credentials or network pivoting.

Recommended Actions

Need Help Assessing Your Exposure?

Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.

Schedule a Consultation
Full security advisory on 247alerts.net →
Axiom Cyber Research
Axiom Cyber Research, LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing elite cybersecurity consulting to the Defense Industrial Base and regulated sectors. Founded by a 20+ year veteran with deep offensive and defensive cyber expertise. Our CVE intelligence program actively tracks emerging vulnerabilities to help organizations prioritize remediation and reduce exposure windows.
Baltimore, MD  ·  axiomcyber.io  ·  247alerts.net  ·  SDVOSB  ·  NAICS 541512