Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3773 articles · 209723 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-73246
kestra-io · kestra

Kestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentials

Description

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndpoint.java serves GET /worker without authentication and serializes the complete live Task object, which can expose commands, environment variables, HTTP headers, connection details, plaintext credentials, and execution identifiers while the main API on port 8080 remains protected. This issue is fixed in 2.0.0-rc6.

Affected Products

VendorProductVersions
kestra-iokestra< 1.3.31

References

  • https://github.com/kestra-io/kestra/security/advisories/GHSA-m65f-q5gj-hg46(x_refsource_CONFIRM)

Related News (1 articles)

Tier C
VulDB23d ago
CVE-2026-73246 | Kestra prior 2.0.0-rc6 WorkerEndpoint WorkerEndpoint.java missing encryption
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-200, CWE-306
PublishedAug 11, 2026
Last enriched23d ago
Trending Score4
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-49869EXPKEV
Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
Trending: 138
HIGHCVE-2026-73247
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata
Trending: 4
HIGHCVE-2026-55839
Kestra: Stored XSS via custom Markdown [[link]] attribute injection
Trending: 4
MEDIUMCVE-2026-73245
Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth
Trending: 3
HIGHCVE-2026-49984
Kestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrary server files via the execution file-download API (`\..\` bypasses the `..` guard)

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026