PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-49984 kestra-io CVE debrief

CVE-2026-49984 is a high-severity vulnerability in Kestra's internal-storage backend. Prior to versions 1.0.45 and 1.3.23, the backend validates user-supplied paths for .. traversal before converting Windows-style backslashes to forward slashes. An attacker can exploit this by smuggling a traversal sequence using backslashes, allowing them to read any file on the server filesystem readable by the Kestra process. This includes sensitive data such as the embedded H2 database, internal storage of other tenants/namespaces, mounted secret files, and process environment credentials.

Vendor
kestra-io
Product
kestra
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-26
Original CVE updated
2026-06-29
Advisory published
2026-06-26
Advisory updated
2026-06-29

Who should care

Users of Kestra, especially those with sensitive data stored in the platform, should be aware of this vulnerability. Authenticated users with the lowest-privilege role can exploit this vulnerability to access sensitive data across all tenants and namespaces.

Technical summary

The vulnerability exists in the local internal-storage backend of Kestra. The backend validates user-supplied paths for .. traversal before converting Windows-style backslashes to forward slashes. An attacker can smuggle a traversal sequence past the guard using backslashes, allowing them to read any file on the server filesystem readable by the Kestra process. This can be exploited by calling GET /api/v1/{tenant}/executions/{executionId}/file?path=… with a malicious path.

Defensive priority

High priority should be given to upgrading Kestra to versions 1.0.45 or 1.3.23. In the meantime, defenders should restrict access to the affected API endpoint and monitor for suspicious activity.

Recommended defensive actions

  • Upgrade Kestra to version 1.0.45 or 1.3.23
  • Restrict access to the affected API endpoint
  • Monitor for suspicious activity
  • Review and update access controls for Kestra users
  • Perform a thorough review of Kestra's storage and filesystem configurations

Evidence notes

The CVE record and NVD detail provide information on the vulnerability. The source item URL provides additional context on the vulnerability. The reference to the GitHub security advisory provides further details on the vulnerability and the fix.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-49984 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-49984

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-49984 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49984

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.