PT-2026-52986 · Kestra · Kestra

·

CVE-2026-55069

·

Published

2026-06-26

·

Updated

2026-07-01

CVSS v3.1

8.7

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kestra versions prior to 1.3.24
Description The BasicAuth authentication component of the Kestra OSS workflow orchestration platform stores passwords using SHA-512, which has a high computation speed. An attacker with read access to the PostgreSQL database can perform an offline brute-force attack to recover the administrator password. In Kubernetes deployments, this can lead to vertical privilege escalation by allowing the attacker to read the cluster ServiceAccount Token and all K8s Secrets.
Recommendations Update to version 1.3.24.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55069
GHSA-M727-PCJM-J28H

Affected Products

Kestra