{"schema_version":1,"title":"Kestra vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 13 vulnerabilities in Kestra: 0 in the last 7 days and 4 in the last 90 days, 4 of them critical and 1 exploited in the wild. The most recent, CVE-2026-55839, was published on 18 August 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/kestra","json_url":"https://junglewise.ai/threats/vendors/kestra.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/kestra","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":6,"all_time":13,"critical":4,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":4,"last_365_days":13},"latest":[{"cve":"CVE-2026-55839","cvss":8.7,"epss":0.0043,"slug":"cve-2026-55839-kestra-stored-xss-via-custom-markdown-link-attribute-injection","title":"Kestra stored XSS via custom Markdown link attribute injection","severity":"high","exploited":false,"published_at":"2026-08-18T16:31:38+00:00","url":"https://junglewise.ai/threats/cve-2026-55839-kestra-stored-xss-via-custom-markdown-link-attribute-injection"},{"cve":"CVE-2026-73247","cvss":8.6,"epss":0.0041,"slug":"cve-2026-73247-kestra-server-side-request-forgery-via-pebble-http-function","title":"Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/fun","severity":"high","exploited":false,"published_at":"2026-08-11T22:19:05.417+00:00","url":"https://junglewise.ai/threats/cve-2026-73247-kestra-server-side-request-forgery-via-pebble-http-function"},{"cve":"CVE-2026-73246","cvss":7.5,"epss":0.006,"slug":"cve-2026-73246-kestra-unauthenticated-worker-endpoint-exposes-task-credentials","title":"Kestra unauthenticated worker endpoint exposes task credentials","severity":"high","exploited":false,"published_at":"2026-08-11T22:19:05.287+00:00","url":"https://junglewise.ai/threats/cve-2026-73246-kestra-unauthenticated-worker-endpoint-exposes-task-credentials"},{"cve":"CVE-2026-73245","cvss":6.5,"epss":0.0033,"slug":"cve-2026-73245-kestra-unauthenticated-management-endpoints-on-port-8081","title":"Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/application.yml serves Mi","severity":"medium","exploited":false,"published_at":"2026-08-11T22:19:05.14+00:00","url":"https://junglewise.ai/threats/cve-2026-73245-kestra-unauthenticated-management-endpoints-on-port-8081"},{"cve":"CVE-2026-55069","cvss":8.7,"slug":"cve-2026-55069-kestra-oss-weak-password-hashing-in-basicauth-component","title":"Kestra OSS weak password hashing in BasicAuth component","severity":"high","exploited":false,"published_at":"2026-06-26T22:16:33.093+00:00","url":"https://junglewise.ai/threats/cve-2026-55069-kestra-oss-weak-password-hashing-in-basicauth-component"},{"cve":"CVE-2026-53577","cvss":6.5,"slug":"cve-2026-53577-kestra-access-control-bypass-in-previewfilefromexecution-endpoint","title":"Kestra access control bypass in previewFileFromExecution endpoint","severity":"medium","exploited":false,"published_at":"2026-06-26T22:16:32.967+00:00","url":"https://junglewise.ai/threats/cve-2026-53577-kestra-access-control-bypass-in-previewfilefromexecution-endpoint"},{"cve":"CVE-2026-53576","cvss":10,"slug":"cve-2026-53576-kestra-authentication-bypass-and-rce-via-path-suffix-manipulation","title":"Kestra authentication bypass and RCE via path-suffix manipulation","severity":"critical","exploited":false,"published_at":"2026-06-26T22:16:32.84+00:00","url":"https://junglewise.ai/threats/cve-2026-53576-kestra-authentication-bypass-and-rce-via-path-suffix-manipulation"},{"cve":"CVE-2026-49984","cvss":7.7,"slug":"cve-2026-49984-kestra-path-traversal-in-localstorage-via-backslash-smuggling","title":"Kestra path traversal in LocalStorage via backslash smuggling","severity":"high","exploited":false,"published_at":"2026-06-26T22:16:32.243+00:00","url":"https://junglewise.ai/threats/cve-2026-49984-kestra-path-traversal-in-localstorage-via-backslash-smuggling"},{"cve":"CVE-2026-49869","cvss":10,"epss":0.021,"slug":"cve-2026-49869-kestra-oss-authentication-bypass-in-authenticationfilter","title":"Kestra OSS authentication bypass in AuthenticationFilter","severity":"critical","exploited":true,"published_at":"2026-06-26T22:16:32.113+00:00","url":"https://junglewise.ai/threats/cve-2026-49869-kestra-oss-authentication-bypass-in-authenticationfilter"},{"cve":"CVE-2026-45807","cvss":7.7,"slug":"cve-2026-45807-kestra-path-traversal-via-url-encoded-characters-in-api-endpoints","title":"Kestra path traversal via URL-encoded characters in API endpoints","severity":"high","exploited":false,"published_at":"2026-06-26T22:16:31.973+00:00","url":"https://junglewise.ai/threats/cve-2026-45807-kestra-path-traversal-via-url-encoded-characters-in-api-endpoints"},{"cve":"CVE-2026-48129","cvss":6.5,"slug":"cve-2026-48129-kestra-path-traversal-in-inputfiles-task-property","title":"Kestra path traversal in inputFiles task property","severity":"medium","exploited":false,"published_at":"2026-06-19T21:16:59.413+00:00","url":"https://junglewise.ai/threats/cve-2026-48129-kestra-path-traversal-in-inputfiles-task-property"},{"cve":"CVE-2026-38428","cvss":9.8,"epss":0.0037,"slug":"cve-2026-38428-kestra-sql-injection-in-flow-search-api-leading-to-rce","title":"Kestra SQL injection in flow search API leading to RCE","severity":"critical","exploited":false,"published_at":"2026-05-05T19:16:21.91+00:00","url":"https://junglewise.ai/threats/cve-2026-38428-kestra-sql-injection-in-flow-search-api-leading-to-rce"},{"cve":"CVE-2026-34612","cvss":9.9,"epss":0.0066,"slug":"cve-2026-34612-kestra-sql-injection-in-flow-search-leads-to-rce","title":"Kestra SQL injection in flow search leads to RCE","severity":"critical","exploited":false,"published_at":"2026-04-03T23:17:04.587+00:00","url":"https://junglewise.ai/threats/cve-2026-34612-kestra-sql-injection-in-flow-search-leads-to-rce"}],"vendor":{"hub":true,"name":"Kestra","slug":"kestra","homepage":"https://kestra.io/","description":"An open-source orchestration and scheduling platform for data and software workflows.","url":"https://junglewise.ai/threats/vendors/kestra"},"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-49869","cvss":10,"epss":0.021,"slug":"cve-2026-49869-kestra-oss-authentication-bypass-in-authenticationfilter","title":"Kestra OSS authentication bypass in AuthenticationFilter","severity":"critical","exploited":true,"published_at":"2026-06-26T22:16:32.113+00:00","url":"https://junglewise.ai/threats/cve-2026-49869-kestra-oss-authentication-bypass-in-authenticationfilter"},{"cve":"CVE-2026-53576","cvss":10,"slug":"cve-2026-53576-kestra-authentication-bypass-and-rce-via-path-suffix-manipulation","title":"Kestra authentication bypass and RCE via path-suffix manipulation","severity":"critical","exploited":false,"published_at":"2026-06-26T22:16:32.84+00:00","url":"https://junglewise.ai/threats/cve-2026-53576-kestra-authentication-bypass-and-rce-via-path-suffix-manipulation"},{"cve":"CVE-2026-34612","cvss":9.9,"epss":0.0066,"slug":"cve-2026-34612-kestra-sql-injection-in-flow-search-leads-to-rce","title":"Kestra SQL injection in flow search leads to RCE","severity":"critical","exploited":false,"published_at":"2026-04-03T23:17:04.587+00:00","url":"https://junglewise.ai/threats/cve-2026-34612-kestra-sql-injection-in-flow-search-leads-to-rce"},{"cve":"CVE-2026-38428","cvss":9.8,"epss":0.0037,"slug":"cve-2026-38428-kestra-sql-injection-in-flow-search-api-leading-to-rce","title":"Kestra SQL injection in flow search API leading to RCE","severity":"critical","exploited":false,"published_at":"2026-05-05T19:16:21.91+00:00","url":"https://junglewise.ai/threats/cve-2026-38428-kestra-sql-injection-in-flow-search-api-leading-to-rce"},{"cve":"CVE-2026-55839","cvss":8.7,"epss":0.0043,"slug":"cve-2026-55839-kestra-stored-xss-via-custom-markdown-link-attribute-injection","title":"Kestra stored XSS via custom Markdown link attribute injection","severity":"high","exploited":false,"published_at":"2026-08-18T16:31:38+00:00","url":"https://junglewise.ai/threats/cve-2026-55839-kestra-stored-xss-via-custom-markdown-link-attribute-injection"},{"cve":"CVE-2026-55069","cvss":8.7,"slug":"cve-2026-55069-kestra-oss-weak-password-hashing-in-basicauth-component","title":"Kestra OSS weak password hashing in BasicAuth component","severity":"high","exploited":false,"published_at":"2026-06-26T22:16:33.093+00:00","url":"https://junglewise.ai/threats/cve-2026-55069-kestra-oss-weak-password-hashing-in-basicauth-component"},{"cve":"CVE-2026-73247","cvss":8.6,"epss":0.0041,"slug":"cve-2026-73247-kestra-server-side-request-forgery-via-pebble-http-function","title":"Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/fun","severity":"high","exploited":false,"published_at":"2026-08-11T22:19:05.417+00:00","url":"https://junglewise.ai/threats/cve-2026-73247-kestra-server-side-request-forgery-via-pebble-http-function"},{"cve":"CVE-2026-49984","cvss":7.7,"slug":"cve-2026-49984-kestra-path-traversal-in-localstorage-via-backslash-smuggling","title":"Kestra path traversal in LocalStorage via backslash smuggling","severity":"high","exploited":false,"published_at":"2026-06-26T22:16:32.243+00:00","url":"https://junglewise.ai/threats/cve-2026-49984-kestra-path-traversal-in-localstorage-via-backslash-smuggling"},{"cve":"CVE-2026-45807","cvss":7.7,"slug":"cve-2026-45807-kestra-path-traversal-via-url-encoded-characters-in-api-endpoints","title":"Kestra path traversal via URL-encoded characters in API endpoints","severity":"high","exploited":false,"published_at":"2026-06-26T22:16:31.973+00:00","url":"https://junglewise.ai/threats/cve-2026-45807-kestra-path-traversal-via-url-encoded-characters-in-api-endpoints"},{"cve":"CVE-2026-73246","cvss":7.5,"epss":0.006,"slug":"cve-2026-73246-kestra-unauthenticated-worker-endpoint-exposes-task-credentials","title":"Kestra unauthenticated worker endpoint exposes task credentials","severity":"high","exploited":false,"published_at":"2026-08-11T22:19:05.287+00:00","url":"https://junglewise.ai/threats/cve-2026-73246-kestra-unauthenticated-worker-endpoint-exposes-task-credentials"}],"generated_at":"2026-09-28T03:07:00.154823+00:00","technologies":[{"name":"Kestra","slug":"kestra","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/kestra"}]}