CVE-2026-53576 is a critical authentication bypass vulnerability in Kestra, an open-source event-driven orchestration platform. In vulnerable versions prior to 1.0.45 and 1.3.21, the REST API authentication filter for /api/v1/** incorrectly treats any request whose path ends with /configs as if it were the public instance-configuration endpoint and forwards the request without enforcing Basic Authentication. Because Kestra uses caller-controlled URL path segments to address resources, an unauthenticated attacker can choose configs as the final path segment on otherwise protected API routes. This bypass can reach flow-creation and execution-trigger endpoints, allowing an anonymous attacker to create a malicious flow containing Shell or Process tasks and then execute it. The resulting task runs as root inside the Kestra container. In default Docker-based deployments where the container has access to the Docker daemon socket, this can extend to host-level compromise.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains two files: a README describing CVE-2026-53576 and a standalone Python exploit script, kestra_exploit.py. The script is the primary entry point and uses the requests library to interact directly with Kestra’s HTTP API. It targets Kestra OSS <= 1.3.20 and abuses an authentication bypass on API paths ending in /configs to achieve unauthenticated remote code execution. Exploit flow: (1) create a malicious Kestra flow containing an io.kestra.plugin.scripts.shell.Commands task with attacker-controlled shell commands, (2) trigger execution of that flow through the executions API, (3) optionally poll execution status, (4) optionally create and run a second flow to test Docker socket access, and (5) optionally delete the malicious flow. The default payload writes id output to /tmp/proof.txt and appends the first line of /etc/shadow, demonstrating command execution and privileged file access. Main capabilities include arbitrary command execution, reading sensitive files, optional post-exploitation Docker daemon probing via /var/run/docker.sock, and cleanup of artifacts. The exploit is operational rather than a simple PoC because it automates the full attack chain and supports custom commands, HTTPS, configurable ports, delays, and cleanup. No external C2 is hardcoded in the script itself; network targets are supplied by the operator at runtime. The README includes illustrative reverse-shell, exfiltration, and cloud-metadata examples, but those are examples rather than built-in behavior.
This repository is a standalone Python-based Kestra vulnerability scanner/exploit utility for CVE-2026-49869 and CVE-2026-53576. It is not tied to a major exploit framework. The codebase is small and organized around a CLI entry point (main.py) and a scanner module (modules/scanner.py) that contains the core target parsing, URL construction, HTTP probing, and reporting logic. Supporting modules provide banners, ANSI colors, and dataclasses for probe/scan results. Primary capability: it detects an authentication bypass caused by Kestra accepting any request path ending in /configs instead of strictly matching /api/v1/configs. The scanner first checks liveness/version via GET /api/v1/configs, then verifies that the normal flows endpoint requires authentication, and finally probes multiple crafted bypass paths under flows, executions, namespaces/kv, dashboards, logs, and templates. If bypass responses differ from the protected baseline, the target is marked vulnerable. Beyond detection, the tool includes active exploitation features. In aggressive mode it sends PUT requests to confirm unauthorized write access by creating a minimal flow or KV entry. With --rce it performs a full exploit chain: deploys a malicious Kestra flow through the bypass path, triggers execution through the executions bypass endpoint, polls logs for a unique marker plus command output such as id and hostname, and then cleans up the flow. The README states a fallback from shell.Commands to python.Script if needed. With --ssrf it deploys a flow containing Pebble http() calls to AWS, GCP, Azure metadata services and localhost/internal endpoints, then checks execution logs for indicators. With --destructive it tests unauthorized DELETE operations against flows, dashboards, and logs. Repository structure: README.md documents the vulnerability, probe matrix, CLI usage, JSON schema, and affected versions. main.py handles argument parsing, single/bulk scan orchestration, JSON report generation, and exit codes. modules/scanner.py is the main implementation and defines constants such as default tenant main, namespace tutorial, auto-expanded ports [8080, 8081, 8088, 8091, 80, 443], request timeout, polling intervals, and URL builder helpers for the vulnerable endpoints. modules/result.py defines ProbeResult and ScanResult dataclasses used throughout reporting. modules/colors.py and modules/banners.py are cosmetic. requirements.txt shows the tool depends mainly on requests, urllib3, and colorama. Overall, this is an operational exploit/scanner rather than a simple detector: it can validate unauthorized read/write access, confirm code execution, test SSRF reachability, and exercise destructive actions against exposed Kestra instances.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content only references a CVE record file and pull request activity for CVE-2026-53576; it does not describe the vulnerability itself or its impact.
An authentication bypass or access control flaw in Kestra where requests to a path ending in "/configs" appear to bypass normal authorization checks on flow-related API endpoints. The content indicates affected versions up to 1.3.20 and a fix in 1.3.21, with a detection template validating unauthorized access behavior.
An unauthenticated remote code execution vulnerability in Kestra caused by an authentication filter bypass on API paths ending in /configs, allowing anonymous attackers to create and execute flows.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.