CVE-2026-53577: Kestra

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the previewFileFromExecution endpoint (GET /api/v1/{tenant}/executions/{executionId}/file/preview) contains an access control bypass that allows any authenticated user to read output files from any other execution within the same tenant, bypassing execution-level and namespace-level isolation. This vulnerability is fixed in 1.0.45 and 1.3.21.

Affected products

  • Kestra Kestra: before 1.0.45 (fixed in 1.0.45); from 1.1.0, before 1.3.21 (fixed in 1.3.21)

Published 2026-06-26. Last modified 2026-07-01.