What is CVE-2026-73246?
A critical vulnerability in Kestra allows unauthenticated access to the GET /worker endpoint, exposing command details and environment variables from live Task objects. This affects versions prior to 2.0.0-rc6 and immediate upgrade is recommended.
Azərbaycanca: Kestra platformasında tapılan kritik boşluq autentifikasiya olmadan GET /worker sorğusu vasitəsilə canlı tapşırıq detallarını, əmr sətirlərini və mühit dəyişənlərini ifşa edir. 2.0.0-rc6 versiyasına qədər təsir göstərir və bu versiyaya təcili yeniləmə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ1
What critical information does CVE-2026-73246 in Kestra expose?
This vulnerability exposes live task details, command lines, and environment variables through an unauthenticated GET /worker request.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.