Kestra configs authentication bypass

Added: 09/04/2026

Background

Kestra is open-source software for data, AI, and infrastructure workflows.

Problem

An authentication bypass vulnerability in the AuthenticationFilter class allows remote unauthenticated attackers to bypass authentication for any request path ending with "configs", leading to arbitrary command execution.

Resolution

Upgrade to Kestra 1.0.45 or 1.3.21 or higher.

References

https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx

Back to exploit index