CVE-CVE-2026-53576
Severity
CRITICAL
CVSS Score
10.0
Description
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and forwards it without a credential check. kestra addresses its resources by URL path segments that the caller chooses (/api/v1/{tenant}/flows/{namespace}, /api/v1/{tenant}/executions/{namespace}/{id}, /api/v1/{tenant}/namespaces/{namespace}/kv/{key}). An...
PoCs for CVE-CVE-2026-53576
Kestra-cve-2026-53576
RCE
0
AtlasVector
2026-09-25