- A security update has been released to address a vulnerability in Kestra.
- Affected products include Kestra OSS versions prior to 1.0.45 And prior to 1.3.21.
- The vulnerability addressed is CVE-2026-49869, a remote code execution vulnerability caused by authentication bypass in
AuthenticationFilter.
- A patch for this vulnerability is available in the latest update.
- As instructed on the reference site, you must update to Kestra OSS version 1.0.45 Or 1.3.21, Which includes the latest Vulnerability Patch.