Kestra's Path Suffix Bug: When a Framework Forgets to Check the Whole Route
Kestra's Path Suffix Bug: When a Framework Forgets to Check the Whole Route A patch released in June 2026 became an urgent remediation item in September. The reason is not that the fix was wrong, but that CISA added the vulnerability to its Known Exploited Vulnerabilities catalog after evidence of real attacks. The case is a useful study in the gap between a patch existing and a risk being…
Kestra, an event-driven orchestration platform, is vulnerable to CVE-2026-49869, a security flaw that allows authenticated and unauthenticated attackers to inject operating system commands. The issue stems from an outdated authentication filter that only checked if a request ended with a specific path, rather than verifying the exact route or the intended HTTP method.
This oversight enabled unauthorized users to trigger workflows, leading to remote code execution with the privileges of the Kestra process. Though a patch for the vulnerability was released in June 2026, it gained urgency in September when the Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog after observing actual attacks.
The gap between the patch's availability and CISA's listing allowed attackers several months to exploit the vulnerability. To mitigate the risk, organizations must ensure they've upgraded to the fixed versions (1.0.45 or 1.3.21) and implement compensating controls such as blocking requests to the vulnerable endpoint at a reverse proxy level.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.