Skip to finding
important · Edge — Workflow

Kestra's unauthenticated workflow path is being used to reach worker-container command execution.

Affects

Kestra OSS workflow-orchestration servers, commonly deployed as containers on application and automation infrastructure

Any route ending in /configs escapes the authentication filter, allowing an unauthenticated caller to create and execute a script workflow as uid 0 in the worker container.

Detail and 3 sources

The service is commonly exposed on TCP port 8080 or a mapped container port.

Microsoft observed workflow-origin shell execution, and CISA added the vulnerability to KEV on September 2. Kestra has published a fix.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 3, 2026