What is CVE-2026-73245?
CVE-2026-73245 is a security vulnerability in Kestra prior to version 2.0.0-rc6. Micronaut management endpoints are served on port 8081 without authentication, allowing unauthorized access to sensitive environment variables via a GET /env request. Users should immediately upgrade to version 2.0.0-rc6 or later.
Azərbaycanca: CVE-2026-73245 Kestra platformunun 2.0.0-rc6 öncəsi versiyalarında aşkarlanmış təhlükəsizlik zəifliyidir. Micronaut idarəetmə endpoint-ləri 8081 portunda autentifikasiya olmadan işlədiyi üçün təcavüzkar `/env` sorğusu ilə həssas mühit dəyişənlərinə icazəsiz giriş əldə edə bilər. İstifadəçilər dərhal 2.0.0-rc6 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of the Kestra platform are affected by CVE-2026-73245?
This vulnerability affects versions of Kestra prior to 2.0.0-rc6.
What can an attacker obtain by exploiting CVE-2026-73245?
An attacker can gain unauthorized access to sensitive environment variables by sending a GET /env request via unauthenticated Micronaut management endpoints on port 8081.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.