PatchSiren cyber security CVE debrief
CVE-2026-49984 kestra-io CVE debrief
CVE-2026-49984 is a high-severity vulnerability in Kestra's internal-storage backend. Prior to versions 1.0.45 and 1.3.23, the backend validates user-supplied paths for .. traversal before converting Windows-style backslashes to forward slashes. An attacker can exploit this by smuggling a traversal sequence using backslashes, allowing them to read any file on the server filesystem readable by the Kestra process. This includes sensitive data such as the embedded H2 database, internal storage of other tenants/namespaces, mounted secret files, and process environment credentials.
- Vendor
- kestra-io
- Product
- kestra
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-26
- Original CVE updated
- 2026-06-29
- Advisory published
- 2026-06-26
- Advisory updated
- 2026-06-29
Who should care
Users of Kestra, especially those with sensitive data stored in the platform, should be aware of this vulnerability. Authenticated users with the lowest-privilege role can exploit this vulnerability to access sensitive data across all tenants and namespaces.
Technical summary
The vulnerability exists in the local internal-storage backend of Kestra. The backend validates user-supplied paths for .. traversal before converting Windows-style backslashes to forward slashes. An attacker can smuggle a traversal sequence past the guard using backslashes, allowing them to read any file on the server filesystem readable by the Kestra process. This can be exploited by calling GET /api/v1/{tenant}/executions/{executionId}/file?path=… with a malicious path.
Defensive priority
High priority should be given to upgrading Kestra to versions 1.0.45 or 1.3.23. In the meantime, defenders should restrict access to the affected API endpoint and monitor for suspicious activity.
Recommended defensive actions
- Upgrade Kestra to version 1.0.45 or 1.3.23
- Restrict access to the affected API endpoint
- Monitor for suspicious activity
- Review and update access controls for Kestra users
- Perform a thorough review of Kestra's storage and filesystem configurations
Evidence notes
The CVE record and NVD detail provide information on the vulnerability. The source item URL provides additional context on the vulnerability. The reference to the GitHub security advisory provides further details on the vulnerability and the fix.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-49984 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-49984
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-49984 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49984
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/kestra-io/kestra/security/advisories/GHSA-qw4v-6w32-xx9h
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.