Junglewise Threat Intelligence

CVE-2026-73246: Kestra unauthenticated worker endpoint exposes task credentials

CVE-2026-73246 · Severity: high · CVSS 7.5 · Published 2026-08-11

Technologies: Kestra. Vendors: Kestra.

Executive brief

Kestra is an open-source workflow orchestration platform that allows organizations to automate and manage data pipelines and scheduled tasks. An unauthenticated endpoint on port 8081 exposes the complete configuration of running tasks, including plaintext passwords, API tokens, environment variables, and database connection details—even when the main API is protected with authentication. An attacker with network access to the management port can passively monitor all running jobs and harvest sensitive credentials without any authentication.

Technical details

The vulnerability is an authentication bypass and sensitive information exposure in Kestra's WorkerEndpoint (/worker GET endpoint on port 8081). The endpoint is marked as non-sensitive by default and returns a fully serialized live Task domain object containing unredacted environment variables, commands, headers, and credentials. The management listener on 8081 operates independently of the main API authentication (port 8080), meaning kestra.server.basic-auth does not protect it—a second, manual endpoints.all.basic-auth configuration is required. Attack vector is unauthenticated network access to port 8081 with no preconditions beyond one running task; the attacker can enumerate all active executions and harvest plaintext secrets. The vulnerability affects Kestra versions ≤1.3.26 and is fixed in 2.0.0-rc6.

Affected products

  • Kestra Kestra <=1.3.26

Timeline

  • 2026-08-07: disclosed
  • 2026-08-11: patched: Fixed in version 2.0.0-rc6

References

Related threats