CVE-2026-53577

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the previewFileFromExecution endpoint (GET /api/v1/{tenant}/executions/{executionId}/file/preview) contains an access control bypass that allows any authenticated user to read output files from any other execution within the same tenant, bypassing execution-level and namespace-level isolation. This vulnerability is fixed in 1.0.45 and 1.3.21.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:kestra:kestra:*:*:*:*:*:*:*:*
cpe:2.3:a:kestra:kestra:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-26 22:16

Updated : 2026-07-01 12:38


NVD link : CVE-2026-53577

Mitre link : CVE-2026-53577

CVE.ORG link : CVE-2026-53577


JSON object : View

Products Affected

kestra

  • kestra
CWE
CWE-863

Incorrect Authorization