CVE-2026-55069Disclosure(kestra / kestra)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch kestra kestra systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth authentication component of the Kestra OSS workflow orchestration platform. An attacker who gains read access to the PostgreSQL database can exploit SHA-512's high computation speed to recover the administrator password offline. In Kubernetes deployments, a successful crack further enables reading of the cluster ServiceAccount Token and all K8s Secrets, achieving vertical privilege escalation. This vulnerability is fixed in 1.3.24.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-916

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kestra

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-06-26); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
kestra

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-06-26: 3Mentions · 2026-06-30: 1Patch / Workaround · 2026-06-30: 1Technical Details · 2026-06-26: 1Technical Details · 2026-06-30: 106-2606-30
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-263
Disclosure3
2026-06-301
Patch1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-55069 Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth authentication component of the Kestra OSS … https://www.cve.org/CVERecord?id=CVE-2026-55069

    Post summary

    The snippet identifies that CVE-2026-55069 affects the BasicAuth authentication component of Kestra prior to version 1.3.24, but it provides no additional technical details, exploit info, or mitigation guidance.

    00010719
    57.7K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-55069 (CVSS 8.7) - Kestra orchestration platform password recovery flaw. Attackers with DB read access can crack admin passwords offline, escalate to K8s secrets in cluster deployments. Patch to v1.3.24+ immediately. #CVE #PatchNow #ThreatIntel https://t.co/X7oSoYgbUX

    Post summary

    The tweet alerts to a high‑severity CVE 2026‑55069 involving a password recovery flaw in Kestra, outlines its technical details, and urges patching to v1.3.24+ immediately.

    0000064
    55 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-55069 Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth authentication component of the Kestra OSS … https://www.cve.org/CVERecord?id=CVE-2026-55069 ----- Traducción: CVE-2026-55069 Kes… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-55069 affecting Kestra’s BasicAuth component before version 1.3.24, with a reference to the CVE record but no exploitation or mitigation details.

    0000031
    89 followersView on X
  • MalwareObserver@MalwareObserver
    Disclosure

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-55069](https://github.com/kestra-io/kestra/security/advisories/GHSA-m727-pcjm-j28h) Kes... https://github.com/kestra-io/kestra/security/advisories/GHSA-m727-pcjm-j28h #Vulnerability #CVE #ZeroDay

    Post summary

    The message announces the discovery of CVE-2026-55069, linking to a GitHub advisory, indicating a new zero‑day vulnerability.

    0000058
    6 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkestrakestra---

Explore more