CVE-2026-53577

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the previewFileFromExecution endpoint (GET /api/v1/{tenant}/executions/{executionId}/file/preview) contains an access control bypass that allows any authenticated user to read output files from any other execution within the same tenant, bypassing execution-level and namespace-level isolation. This vulnerability is fixed in 1.0.45 and 1.3.21.
Configurations

No configuration.

History

27 Jun 2026, 04:17

Type Values Removed Values Added
References () https://github.com/kestra-io/kestra/security/advisories/GHSA-r6v3-xxwj-9h42 - () https://github.com/kestra-io/kestra/security/advisories/GHSA-r6v3-xxwj-9h42 -

26 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-26 22:16

Updated : 2026-06-27 04:17


NVD link : CVE-2026-53577

Mitre link : CVE-2026-53577

CVE.ORG link : CVE-2026-53577


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization