The Suffix That Skipped Authentication: Kestra CVE-2026-49869 and Why Path Matching Is Not Authorisation
An authentication filter that decides based on how a URL ends is not checking who you are. It is checking how a string looks. Kestra OSS shipped exactly that pattern, and in September 2026 CISA added the resulting vulnerability to its Known Exploited Vulnerabilities catalog with a three-day federal remediation deadline.
The defect
CVE-2026-49869 sits in Kestra's AuthenticationFilter. The filter used request.getPath().endsWith("/configs") to decide whether a request targeted a public configuration endpoint and should skip Basic Auth. The intent was to exempt one specific endpoint. The implementation exempted every API path ending in those characters.
Because Kestra lets callers define resource identifiers, an attacker can construct a protected path that also ends in /configs. Authentication is skipped. The attacker can then create and execute workflows without credentials.
The official fix commit normalises the path first and then matches the configuration endpoint exactly, as /api/v1/configs, and adds negative regression tests confirming that other paths ending in /configs still return 401.
Why authentication bypass becomes code execution here
For a content site, skipping authentication might mean reading or writing content. For a workflow orchestrator, the consequences are different in kind. Kestra exists to define and schedule workflows and to run shell, Python and Node.js tasks. It connects to databases, cloud services, message systems and internal APIs, and it stores configuration, variables and run logs.
Running scripts is the product. So an authentication bypass that grants workflow creation and execution does not need a separate command injection step. The platform already provides controlled code execution; the flaw is that the control was removed.
The official CVSS vector reflects this: network reachable, low complexity, no privileges required, no user interaction, with high impact across confidentiality, integrity and availability.
What to be careful about when describing impact
There is a temptation to describe this as "root on the host." The more accurate statement is that the attacker can execute commands within the worker container's boundary. Whether that reaches the host depends on mounts, capabilities, whether a container socket is exposed, the service account in use and the runtime configuration.
Similarly, CISA's KEV listing confirms real-world exploitation. It does not mean every exposed instance was compromised, and it does not publish the full details of the observed activity. Whether an attacker can reach cloud credentials depends on the worker's network reachability and its actual authorisation.
Being precise about these boundaries matters, because it determines what you check during incident response.
Remediation
- Upgrade to a fixed release. The advisory lists 1.0.45 and 1.3.21 as fixes, with affected ranges below 1.0.45 and from 1.1.0 to below 1.3.21.
- Restrict API access at the network layer while patching. Allow only trusted management entry points, and enforce authentication at an upstream proxy.
- Do not rely on version scanning alone. Check for anomalous workflows, unexpected execution records, key-value store changes, deleted logs and script tasks from unknown sources.
- Reduce the worker's reach. If the container can reach a metadata endpoint or a broad internal network, the impact of any execution flaw is larger than it needs to be.
The design question this raises
The interesting part of this incident is not the specific string. It is the question the case study poses: when a request passes through a CDN, a WAF, a reverse proxy, an API gateway, a framework filter and finally a business route, which layer decides what the request is?
If each layer answers with its own string comparison, the definitions will eventually disagree, and an attacker only needs one disagreement. The durable approach is to make the authorisation decision against the resolved route rather than against a textual property of the path. The fix commit is a small illustration of the principle: normalise, then match exactly.
References
- Kestra GitHub Security Advisory GHSA-5vc5-wxxq-3fjx for CVE-2026-49869
- NVD entry for CVE-2026-49869
- CISA Known Exploited Vulnerabilities Catalog, Kestra entry added 2 September 2026
- Kestra official fix commit and release notes for 1.0.45 and 1.3.21
Top comments (0)