The Workflow Engine Let Attackers Write Their Own Jobs

CISA says attackers are exploiting a Kestra authentication bypass that lets unauthenticated requests create workflows and execute commands as root inside the worker container.

CISA says attackers are exploiting a Kestra authentication bypass that lets unauthenticated requests create workflows and execute commands as root inside the worker container.
© 2026 BlackTree. Independent technical publication.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
These cookies are needed for adding comments on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
Jetpack's built-in visitor analytics. It records page views, referring sites, search terms, and outbound link clicks, and also carries the shared visitor-tracking library used by Jetpack Instant Search and WooCommerce Analytics.
Service URL: automattic.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.