{
  "id": 11641702,
  "title": "The Suffix That Skipped Authentication: Kestra CVE-2026-49869 and Why Path Matching Is Not Authorisation",
  "url": "https://urgent.news/2026/10/03/the-suffix-that-skipped-authentication-kestra-cve-2026-49869-and-why",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-03T08:40:26.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/kozhevniko/the-suffix-that-skipped-authentication-kestra-cve-2026-49869-and-why-path-matching-is-not-4fba"
  },
  "original_language": "en",
  "account": "Kestra, an open-source workflow orchestrator, recently released a critical vulnerability CVE-2026-49869. This flaw is related to how Kestra handles URL paths and authentication. The AuthenticationFilter component in Kestra checks if a request is targeting a specific configuration endpoint by evaluating if the URL path ends with '/configs'. This implementation assumes that only one endpoint should bypass Basic Auth authentication. However, the design flaw allows any API path ending in '/configs' to bypass authentication, not just the intended endpoint. This means an attacker could construct a URL that ends in '/configs' to gain unauthorized access and execute workflows without proper credentials. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog in September 2026, with a three-day federal remediation deadline. The CVSS vector for this vulnerability is high impact across confidentiality, integrity, and availability due to its low complexity, network reachability, and no requirement for user interaction. To mitigate the risk, Kestra users are advised to upgrade to versions 1.0.45 or 1.3.21. As an interim measure, restricting API access at the network layer, enforcing authentication at an upstream proxy, and implementing additional checks for anomalous workflows or unexpected activities can help reduce the attack surface.",
  "summary": "The Suffix That Skipped Authentication: Kestra CVE-2026-49869 and Why Path Matching Is Not Authorisation An authentication filter that decides based on how a URL ends is not checking who you are. It is checking how a string looks. Kestra OSS shipped exactly that pattern, and in September 2026 CISA added the resulting vulnerability to its Known Exploited Vulnerabilities catalog with a three-day…",
  "key_points": [
    "Kestra workflow orchestrator has critical CVE-2026-49869 vulnerability",
    "AuthenticationFilter bypasses Basic Auth for any /configs API path",
    "Upgrade to 1.0.45 or 1.3.21, restrict API access to mitigate risk"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}