CVE-2026-53576 - Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass
CVE ID :CVE-2026-53576 Published : June 26, 2026, 8:54 p.m. | 4 hours, 17 minutes ago Description :Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends...