CVE-2026-49984Patch(kestra / kestra)

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch kestra kestra systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied paths for .. traversal before it converts Windows-style backslashes to forward slashes. An attacker can therefore smuggle a traversal sequence past the guard using backslashes (..\..\..\); the guard sees a harmless string, and the path is only rewritten to ../../../ after validation, immediately before the file is opened. Any authenticated user who can view an execution (the lowest-privilege role) can call GET /api/v1/{tenant}/executions/{executionId}/file?path=… and read any file on the server filesystem readable by the Kestra process, outside the storage sandbox and across every tenant and namespace. This includes the embedded H2 database (all flows, all users, all stored secrets), internal storage of every other tenant/namespace, mounted secret files, and the process environment (/proc/self/environ) which contains configured database and secret-backend credentials. It is a complete breach of Kestra's storage isolation and multi-tenancy boundary. This vulnerability is fixed in 1.0.45 and 1.3.23.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-180CWE-200

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kestra

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-06-26); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
kestra

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-26: 2Mentions · 2026-06-30: 1Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-06-30: 1Technical Details · 2026-06-26: 2Technical Details · 2026-06-30: 106-2606-30
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-262
Disclosure1Patch1
2026-06-301
Patch1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-49984 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied paths for .. tra… https://www.cve.org/CVERecord?id=CVE-2026-49984 ----- Traducción: CVE-2026-49984 Kes… http://infoflow.cloud`

    Post summary

    A brief note references CVE-2026-49984 affecting Kestra versions prior to 1.0.45 and 1.3.23, with a link to the CVE record, but no PoC, exploit, or mitigation details are provided.

    0001031
    89 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-49984 (CVSS 7.7) - Path traversal in Kestra orchestration platform allows authenticated users to read ANY file on server, including secrets & credentials. Affects <1.0.45 & <1.3.23. Patch immediately! #CVE #Vulnerability #PatchNow https://t.co/VgGJBgKKm4

    Post summary

    The tweet alerts users about CVE-2026-49984, a path traversal flaw in Kestra that lets authenticated users read any file, and urges immediate patching.

    0000048
    55 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-49984 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied paths for .. tra… https://www.cve.org/CVERecord?id=CVE-2026-49984

    Post summary

    CVE-2026-49984 is a path validation flaw in Kestra, addressed in releases 1.0.45 and 1.3.23.

    00000680
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkestrakestra---

Explore more