## Overview
CISA added CVE-2026-49869 to its Known Exploited Vulnerabilities (KEV) catalog on September 2, 2026. This move signals a federal deadline for agencies to address the vulnerability. The flaw affects Kestra OSS, an open-source orchestration platform, and poses a significant risk due to its potential for exploitation.
## Technical Details
The vulnerability lies in the AuthenticationFilter of Kestra OSS. In versions prior to 1.0.45 and 1.3.21, the filter uses `request.getPath().endsWith("/configs")` to allow access to the public configuration endpoint without Basic Authentication. This suffix match is insufficient, enabling any API path ending with "configs" to bypass authentication entirely. As a result, an unauthenticated remote attacker can exploit this flaw to create and execute arbitrary workflows. The presence of enabled script execution plugins, such as `plugin-script-shell` and `plugin-script-python`, exacerbates the risk by allowing remote code execution as root within the Kestra worker container.
## Impact
The impact of CVE-2026-49869 is severe, with a CVSS score of 10.0 indicating critical vulnerability status. Attackers can exploit this flaw to gain unauthorized access and execute commands on affected systems. The ability to run arbitrary workflows without credentials poses a significant threat to the integrity and security of the orchestration platform.
## Mitigation
Defenders should prioritize updating Kestra OSS to versions 1.0.45 or 1.3.21 to mitigate this vulnerability. Organizations should also review their configurations and ensure that any public endpoints are properly secured against unauthorized access. Regular security audits and monitoring for unusual activity can help identify potential exploitation attempts.
CSURFACE Threat Sensor