CVE-2026-73245: Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth

Published Aug 11, 2026
·
Updated

Summary Kestra's Micronaut management endpoints are served on port 8081 with no authentication, even when the main API (port 8080) has basic-auth enabled. Anyone who can reach :8081 can read GET /env (full resolved environment/configuration) and mutate runtime state via POST /loggers/{name} (change log levels), among the other management endpoints. Enabling basic-auth creates a false sense of protection because the auth filter only covers /api/v1/ on 8080 and never applies to the 8081 management port. The shipped repository contains no statement that 8081 is management-only / must-not-be-exposed, and the vendor's reference docker-compose.yml publishes it with no warning. Affected - Product: Kestra (kestra-io/kestra), an open-source orchestration/data-pipeline platform (Java / Micronaut). - Version: v1.3.29 (confirmed); the management-port exposure is an insecure default of the shipped configuration. - No fix at time of report. Technical detail Kestra runs the Micronaut management/actuator endpoints on a separate HTTP port 8081. The authentication filter (basic-auth, when configured) is scoped to the main API on port 8080 (/api/v1/) and does not apply to 8081. As a result: - GET http://<host>:8081/env returns the full resolved environment/configuration (property sources), unauthenticated. - POST http://<host>:8081/loggers/{name} changes a logger's level at runtime, unauthenticated (a state-changing operation). - The other Micronaut management endpoints on 8081 are similarly reachable. The shipped application.yml comments, SECURITY.md, and the vendor's reference docker-compose.yml do not warn that 8081 must be kept internal, and the reference compose publishes 8081, so a deployment that enables basic-auth on the API still exposes the management port with no auth. Impact An unauthenticated network client that can reach port 8081 can read the full application configuration/environment (/env) and change runtime logging (/loggers), and reach the other management endpoints — an authentication-bypass on the management surface. (Sensitive credential values in /env are masked, so this is scored without a full-secret-read confidentiality impact.) Proof of concept Reproduced live on Kestra v1.3.29 with basic-auth enabled on the main API. Unauthenticated GET http://<host>:8081/env returned 200 with the resolved configuration/property sources, and POST http://<host>:8081/loggers/{name} returned 200 and changed the logger level — both with no credentials. The equivalent main-API request on 8080 returned 401 (control), confirming the auth filter covers only the API port and not the 8081 management port. (Credential values in /env were masked.) Full request/response captures available on request. Remediation Apply authentication to the management port (bind the Micronaut management endpoints behind the same auth as the API, or require a separate management credential), and by default bind port 8081 to loopback only. At minimum, document prominently (SECURITY.md, application.yml, the reference docker-compose) that port 8081 must never be exposed to untrusted networks, and do not publish 8081 in the reference compose. Credit Reported by Santosh Kumar Puppala (GitHub: https://github.com/Santoshkumarpuppala).

Other sources

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/application.yml serves Micronaut management endpoints on port 8081 without authentication even when Basic Auth protects /api/v1/ on port 8080, allowing unauthenticated GET /env requests to disclose resolved configuration and POST /loggers/{name} requests to change runtime log levels. This issue is fixed in 2.0.0-rc6.

— MITRE

Affected Software

2 affected componentsFixes available
Kestra Kestra<2.0.0-rc6
maven/io.kestra:kestra<2.0.0
2.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/io.kestra:kestra to a version that resolves this vulnerability.

    Fixed in 2.0.0
  2. Upgrade

    Upgrade kestra-io/kestra to a version that resolves this vulnerability.

    Fixed in 2.0.0-rc6
  3. Configuration

    Update Kestra configuration so Micronaut management endpoints served on port 8081 are bound to loopback only (not publicly reachable), preventing unauthenticated access to endpoints like GET /env and POST /loggers/{name}.

    Kestra Micronaut management endpoints (port 8081) management port binding = bind port 8081 to loopback only
  4. Configuration

    Apply authentication to the Micronaut management endpoints on port 8081 by binding them behind the same auth as the API (or requiring a separate management credential), so the auth filter no longer applies only to /api/v1/** on port 8080.

    Kestra Micronaut management endpoints (port 8081) management endpoint authentication = require authentication (same auth as API or separate management credential)
  5. Configuration

    Ensure the reference docker-compose.yml does not publish port 8081 to the host/network; keep port 8081 internal so untrusted clients cannot reach it.

    reference docker-compose.yml / documentation publish management port 8081 = do not publish 8081 in reference compose
  6. Configuration

    Prominently document in SECURITY.md, application.yml, and the reference docker-compose that port 8081 must never be exposed to untrusted networks, because management endpoints on 8081 bypass API basic-auth.

    SECURITY.md / application.yml security documentation for port 8081 exposure = prominently document that port 8081 must never be exposed to untrusted networks

Event History

Aug 11, 2026
CVE Published
via MITRE·09:36 PM
Data Sourced
via MITRE·09:36 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:19 PM
DescriptionSeverityWeakness
Sep 17, 2026
Advisory Published
via GitHub·05:17 PM
Data Sourced
via GitHub·05:17 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the risk level of CVE-2026-73245?

The risk level of CVE-2026-73245 is categorized as medium with a CVSS score of 6.5.

2

What endpoints are exposed in CVE-2026-73245?

CVE-2026-73245 exposes the /env and /loggers management endpoints on port 8081.

3

How do I fix CVE-2026-73245?

To fix CVE-2026-73245, upgrade Kestra to version 2.0.0-rc6 or later.

4

What vulnerabilities exist with CVE-2026-73245?

CVE-2026-73245 allows unauthenticated access to sensitive management information due to bypassing API basic-auth.

5

Is there a workaround for CVE-2026-73245?

As a workaround for CVE-2026-73245, you can restrict access to port 8081 via firewall rules until the software is updated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203