CVE-2026-53577
EUVD-2026-3991826.06.2026, 22:16
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the previewFileFromExecution endpoint (GET /api/v1/{tenant}/executions/{executionId}/file/preview) contains an access control bypass that allows any authenticated user to read output files from any other execution within the same tenant, bypassing execution-level and namespace-level isolation. This vulnerability is fixed in 1.0.45 and 1.3.21.EnginsightAffected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| kestra | kestra | 𝑥 < 1.0.45 |
| kestra | kestra | 1.1.0 ≤ 𝑥 < 1.3.21 |
𝑥
= Vulnerable software versions