id: CVE-2026-53576 info: name: Kestra <= 1.3.20 - Remote Code Execution author: 0x_Akoko,pdteam,aryu-ru severity: critical description: | Kestra <= 1.3.20 contains an authentication bypass caused by misclassification of /configs endpoint in REST API filter, letting unauthenticated attackers create and execute root-level tasks, exploit requires unauthenticated access to /configs endpoint. impact: | Unauthenticated attackers can execute arbitrary code as root inside the container, potentially compromising the host via Docker socket access. remediation: | Update to versions 1.0.45 or 1.3.21 or later. reference: - https://nvd.nist.gov/vuln/detail/CVE-2026-53576 - https://github.com/kestra-io/kestra/security/advisories/GHSA-2q47-568g-9h4f classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2026-53576 epss-score: 0.03189 epss-percentile: 0.87253 cwe-id: CWE-306 metadata: verified: true max-request: 2 vendor: kestra product: kestra shodan-query: title:"Kestra" fofa-query: title="Kestra" tags: cve,cve2026,kestra,rce,oast,intrusive,vkev flow: http(1) && http(2) && http(3) http: - raw: - | GET / HTTP/1.1 Host: {{Hostname}} host-redirects: true max-redirects: 3 matchers: - type: dsl dsl: - 'status_code == 200' - 'contains_any(body, "KESTRA", "