{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-49869",
  "revision": 1,
  "title": "Kestra — Authentication Bypass to Unauthenticated Root RCE",
  "summary": "Kestra's authentication filter exempts any request path ending in /configs, not only the real public config endpoint, so an unauthenticated attacker can create and run workflows and, through the default shell and python script plugins, run code as root in the worker container.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 10,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.01917,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2026-09-02",
    "prerequisites": "Network access to the Kestra web interface; no credentials needed"
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "kestra >= 1.0.45",
      "kestra >= 1.3.21"
    ]
  },
  "mitre_attack": [
    "T1190",
    "T1059"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Upgrade Kestra to 1.0.45 or 1.3.21 now; it is exploited in the wild, so keep the instance off the internet until patched and hunt for workflows and executions you did not create.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-49869",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-49869",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-49869",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "claude-code"
    },
    {
      "fields": [
        "title"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-49869",
      "retrieved_at": "2026-09-20T11:09:51.520Z",
      "confidence": "high",
      "extractor": "human"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49869",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "exploit",
      "url": "https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx"
    }
  ],
  "published_at": "2026-06-26T22:16:32.113Z",
  "issued_at": "2026-09-20T10:52:56.734Z",
  "tags": [
    "kestra",
    "authentication-bypass",
    "command-injection",
    "workflow-orchestration"
  ]
}
