CVE-2026-53576

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and forwards it without a credential check. kestra addresses its resources by URL path segments that the caller chooses (/api/v1/{tenant}/flows/{namespace}, /api/v1/{tenant}/executions/{namespace}/{id}, /api/v1/{tenant}/namespaces/{namespace}/kv/{key}). An anonymous caller picks the literal configs as the final segment, and the request bypasses Basic-Auth entirely. Because the bypass reaches the flow-create and execution-trigger routes, an unauthenticated caller creates a flow containing a Shell or Process task and runs it. The task executes as root inside the kestra container. The official docker-compose.yml mounts /var/run/docker.sock, so root in the container reaches the host Docker daemon. This vulnerability is fixed in 1.0.45 and 1.3.21.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:kestra:kestra:*:*:*:*:*:*:*:*
cpe:2.3:a:kestra:kestra:*:*:*:*:*:*:*:*

History

01 Jul 2026, 12:39

Type Values Removed Values Added
References () https://github.com/kestra-io/kestra/security/advisories/GHSA-2q47-568g-9h4f - () https://github.com/kestra-io/kestra/security/advisories/GHSA-2q47-568g-9h4f - Exploit, Vendor Advisory
CPE cpe:2.3:a:kestra:kestra:*:*:*:*:*:*:*:*
First Time Kestra kestra
Kestra

29 Jun 2026, 16:16

Type Values Removed Values Added
References () https://github.com/kestra-io/kestra/security/advisories/GHSA-2q47-568g-9h4f - () https://github.com/kestra-io/kestra/security/advisories/GHSA-2q47-568g-9h4f -

26 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-26 22:16

Updated : 2026-07-01 12:39


NVD link : CVE-2026-53576

Mitre link : CVE-2026-53576

CVE.ORG link : CVE-2026-53576


JSON object : View

Products Affected

kestra

  • kestra
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-288

Authentication Bypass Using an Alternate Path or Channel