10 min read
KestraCVE-2026-49869+6 more
One endsWith Call Away From Root: The Kestra Auth Bypass Attackers Are Already Using
Kestra's auth filter whitelisted /configs with a suffix match instead of an exact one, so any API path ending in "configs" skipped authentication — and since Kestra runs shell and Python scripts by default, that one line is unauthenticated root RCE. CISA confirms it's already being used for reverse shells and cryptomining.
Sep 14, 20260