Vendor
Kestra vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 13 vulnerabilities in Kestra: 0 in the last 7 days and 4 in the last 90 days, 4 of them critical and 1 exploited in the wild. The most recent, CVE-2026-55839, was published on 18 August 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 4
- Critical, all time
- 4
- Exploited in the wild
- 1
About Kestra
An open-source orchestration and scheduling platform for data and software workflows.
Kestra technologies
- Kestra12
Latest Kestra vulnerabilities
- CVE-2026-55839: Kestra stored XSS via custom Markdown link attribute injectionhighCVSS 8.7EPSS 0.4%
- CVE-2026-73247: Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's…highCVSS 8.6EPSS 0.4%
- CVE-2026-73246: Kestra unauthenticated worker endpoint exposes task credentialshighCVSS 7.5EPSS 0.6%
- CVE-2026-73245: Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's…mediumCVSS 6.5EPSS 0.3%
- CVE-2026-55069: Kestra OSS weak password hashing in BasicAuth componenthighCVSS 8.7
- CVE-2026-53577: Kestra access control bypass in previewFileFromExecution endpointmediumCVSS 6.5
- CVE-2026-53576: Kestra authentication bypass and RCE via path-suffix manipulationcriticalCVSS 10
- CVE-2026-49984: Kestra path traversal in LocalStorage via backslash smugglinghighCVSS 7.7
- CVE-2026-49869: Kestra OSS authentication bypass in AuthenticationFiltercriticalexploited in the wildCVSS 10EPSS 2.1%
- CVE-2026-45807: Kestra path traversal via URL-encoded characters in API endpointshighCVSS 7.7
- CVE-2026-48129: Kestra path traversal in inputFiles task propertymediumCVSS 6.5
- CVE-2026-38428: Kestra SQL injection in flow search API leading to RCEcriticalCVSS 9.8EPSS 0.4%
- CVE-2026-34612: Kestra SQL injection in flow search leads to RCEcriticalCVSS 9.9EPSS 0.7%
Most severe Kestra vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-49869: Kestra OSS authentication bypass in AuthenticationFiltercriticalexploited in the wildCVSS 10EPSS 2.1%
- CVE-2026-53576: Kestra authentication bypass and RCE via path-suffix manipulationcriticalCVSS 10
- CVE-2026-34612: Kestra SQL injection in flow search leads to RCEcriticalCVSS 9.9EPSS 0.7%
- CVE-2026-38428: Kestra SQL injection in flow search API leading to RCEcriticalCVSS 9.8EPSS 0.4%
- CVE-2026-55839: Kestra stored XSS via custom Markdown link attribute injectionhighCVSS 8.7EPSS 0.4%
- CVE-2026-55069: Kestra OSS weak password hashing in BasicAuth componenthighCVSS 8.7
- CVE-2026-73247: Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's…highCVSS 8.6EPSS 0.4%
- CVE-2026-49984: Kestra path traversal in LocalStorage via backslash smugglinghighCVSS 7.7
- CVE-2026-45807: Kestra path traversal via URL-encoded characters in API endpointshighCVSS 7.7
- CVE-2026-73246: Kestra unauthenticated worker endpoint exposes task credentialshighCVSS 7.5EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 3 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/kestra.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Kestra vulnerabilities", https://junglewise.ai/threats/vendors/kestra, 28 September 2026.