CISA Adds Kestra OSS Vulnerability to Actively Exploited Vulnerabilities List
CVE-2026-49869 allows unauthenticated attackers to bypass Basic Auth, create workflows and, under certain conditions, execute commands in the worker. Versions 1.0.45 and 1.3.21 fix the issue.

The Kestra OSS vulnerability identified as CVE-2026-49869 was added to the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog on September 2, 2026. The entry means that CISA has evidence it is being exploited in the wild. On internet-accessible instances, the issue may allow an unauthenticated attacker to create and run workflows.
The vulnerability affects the Basic Auth mechanism. Incorrect comparison of a path ending in /configs allows authentication to be bypassed without credentials. If scripting plugins are available in the deployment, the result may be remote command execution in the worker environment.
Kestra OSS vulnerability: which versions need to be fixed
Kestra OSS versions before 1.0.45 and versions 1.1.0 through before 1.3.21 are vulnerable. Fixes are available in releases 1.0.45 and 1.3.21.
Operators should prioritize updating instances to the applicable fixed version and check whether their systems show signs of unauthorized workflow creation or execution. Deployments in which workers can access internal services, data or secrets are especially relevant.
- Version 1.0.x: update to at least 1.0.45.
- Versions 1.1.0 through before 1.3.21: update to at least 1.3.21.
- Instances accessible from the internet should receive particular priority.
KEV confirms recorded exploitation
The KEV catalog collects vulnerabilities that CISA considers exploited. For organizations subject to CISA’s binding directives, the agency set a remediation deadline of September 5, 2026. This deadline is not generally binding on all operators, but inclusion in KEV is a practical signal to address the issue urgently.
Microsoft labeled this vulnerability, with a high degree of confidence, as a likely initial-access vector in the Kestra compromise. CISA did not disclose a specific group, scope or timeframe for the exploitation in its entry.
It is also not confirmed that the vulnerability was used in ransomware campaigns; the KEV catalog lists this item as unknown. Inclusion of the vulnerability in KEV itself does not mean that attackers compromised every publicly accessible Kestra instance.
Risk stems from the role of workers
Kestra is a workflow orchestration platform. Successful exploitation therefore may not stop at bypassing login to the interface: an attacker can create and run a workflow. When scripting plugins are available, this capability extends to executing commands in the worker.
The scope of impact is therefore tied to the access permissions and available resources of the specific worker. In environments where a worker communicates with internal services or handles secrets and data, this warrants a more thorough review for possible compromise after updating.
Additional information may come from public indicators of compromise, detection rules or more detailed forensic and configuration recommendations from Kestra. For now, the immediately confirmed steps are to deploy the fixed release and check for suspicious workflows or worker activity.
Sources
- CISA Known Exploited Vulnerabilities Catalog – Confirms the addition of CVE-2026-49869 to KEV on September 2, 2026, the September 5 deadline and recorded exploitation.
- GitHub Security Advisory GHSA-5vc5-wxxq-3fjx – Describes the authentication flaw, the possibility of unauthenticated workflow execution and fixed versions 1.0.45 and 1.3.21.
- NVD CVE-2026-49869 – Confirms the CVE identifier, affected versions and the technical impact, including remote code execution.
- Microsoft Security Blog – Provides an independent analysis of the compromise, in which Microsoft assesses exploitation of CVE-2026-49869 as likely initial access.
Verified and updated: 09/03/2026 06:25



