Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the previewFileFromExecution endpoint (GET /api/v1/{tenant}/executions/{executionId}/file/preview) contains an access control bypass that allows any authenticated user to read output files from any other execution within the same tenant, bypassing execution-level and namespace-level isolation. This vulnerability is fixed in 1.0.45 and 1.3.21.
References
Configurations
No configuration.
History
27 Jun 2026, 04:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/kestra-io/kestra/security/advisories/GHSA-r6v3-xxwj-9h42 - |
26 Jun 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-26 22:16
Updated : 2026-06-27 04:17
NVD link : CVE-2026-53577
Mitre link : CVE-2026-53577
CVE.ORG link : CVE-2026-53577
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
