Tag
critical
advisory
Authentication Bypass and RCE in Kestra OSS
1 rule 3 TTPs 1 CVE 1 IOCKestra OSS versions 1.3.20 and below are vulnerable to an authentication bypass via an incorrectly implemented filter, enabling unauthenticated remote code execution with root privileges.
Kestra OSS
cve-2026-53576
rce
authentication-bypass
kestra
1r
3t
1c
1i
high
advisory
Kestra Orchestration Platform XSS Vulnerability (CVE-2026-33664)
2 rules 1 TTPKestra versions up to 1.3.3 are vulnerable to a cross-site scripting (XSS) vulnerability (CVE-2026-33664) allowing arbitrary JavaScript execution by viewing crafted flow metadata.
kestra
xss
cve-2026-33664
orchestration
2r
1t