PT-2026-70937 · Kestra · Kestra
CVE-2026-73246
·
Published
2026-08-11
·
Updated
2026-08-11
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kestra versions prior to 2.0.0-rc6
Description
An unauthenticated endpoint allows the serialization of the complete live Task object. This can lead to the exposure of sensitive information, including commands, environment variables, HTTP headers, connection details, plaintext credentials, and execution identifiers. The issue occurs at the 'GET /worker' endpoint, while the main API on port 8080 remains protected.
Recommendations
Update to version 2.0.0-rc6.
Exploit
Fix
Missing Authentication
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kestra