kestra是Kestra公司开源的一个工作流自动化平台。 kestra-io kestra存在授权问题漏洞,该漏洞源于previewFileFromExecution端点存在访问控制绕过,可能导致任何经过身份验证的用户读取同一租户内其他执行的输出文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53576 | 10.0 CRITICAL | Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass |
| CVE-2026-49869 | 10.0 CRITICAL | Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `Authentication |
| CVE-2026-55069 | 8.7 HIGH | Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack |
| CVE-2026-45807 | 7.7 HIGH | Kestra: Path traversal via URL-encoded "%2E%2E" in execution and namespace file endpoints |
| CVE-2026-49984 | 7.7 HIGH | Kestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrary s |
No comments yet