⚠️CVE-2026-49869 (CVSS 10.0)⚠️ Unauthenticated RCE in Kestra OSS workers. A `/configs` suffix bypasses Basic Auth, letting attackers create and run shell-task flows. It affects OSS instances using Basic Auth when an attacker can reach the API; no credentials or pre-existing
@EQST
1 grabs
No comments yet
Say something. You’re first.