CVE-2026-73245: Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth
Summary Kestra's Micronaut management endpoints are served on port 8081 with no authentication, even when the main API (port 8080) has basic-auth enabled. Anyone who can reach :8081 can read GET /env (full resolved environment/configuration) and mutate runtime state via POST /loggers/{name} (change log levels), among the other management endpoints. Enabling basic-auth creates a false sense of protection because the auth filter only covers /api/v1/ on 8080 and never applies to the 8081 management port. The shipped repository contains no statement that 8081 is management-only / must-not-be-exposed, and the vendor's reference docker-compose.yml publishes it with no warning. Affected - Product: Kestra (kestra-io/kestra), an open-source orchestration/data-pipeline platform (Java / Micronaut). - Version: v1.3.29 (confirmed); the management-port exposure is an insecure default of the shipped configuration. - No fix at time of report. Technical detail Kestra runs the Micronaut management/actuator endpoints on a separate HTTP port 8081. The authentication filter (basic-auth, when configured) is scoped to the main API on port 8080 (/api/v1/) and does not apply to 8081. As a result: - GET http://<host>:8081/env returns the full resolved environment/configuration (property sources), unauthenticated. - POST http://<host>:8081/loggers/{name} changes a logger's level at runtime, unauthenticated (a state-changing operation). - The other Micronaut management endpoints on 8081 are similarly reachable. The shipped application.yml comments, SECURITY.md, and the vendor's reference docker-compose.yml do not warn that 8081 must be kept internal, and the reference compose publishes 8081, so a deployment that enables basic-auth on the API still exposes the management port with no auth. Impact An unauthenticated network client that can reach port 8081 can read the full application configuration/environment (/env) and change runtime logging (/loggers), and reach the other management endpoints — an authentication-bypass on the management surface. (Sensitive credential values in /env are masked, so this is scored without a full-secret-read confidentiality impact.) Proof of concept Reproduced live on Kestra v1.3.29 with basic-auth enabled on the main API. Unauthenticated GET http://<host>:8081/env returned 200 with the resolved configuration/property sources, and POST http://<host>:8081/loggers/{name} returned 200 and changed the logger level — both with no credentials. The equivalent main-API request on 8080 returned 401 (control), confirming the auth filter covers only the API port and not the 8081 management port. (Credential values in /env were masked.) Full request/response captures available on request. Remediation Apply authentication to the management port (bind the Micronaut management endpoints behind the same auth as the API, or require a separate management credential), and by default bind port 8081 to loopback only. At minimum, document prominently (SECURITY.md, application.yml, the reference docker-compose) that port 8081 must never be exposed to untrusted networks, and do not publish 8081 in the reference compose. Credit Reported by Santosh Kumar Puppala (GitHub: https://github.com/Santoshkumarpuppala).
Other sources
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/application.yml serves Micronaut management endpoints on port 8081 without authentication even when Basic Auth protects /api/v1/ on port 8080, allowing unauthenticated GET /env requests to disclose resolved configuration and POST /loggers/{name} requests to change runtime log levels. This issue is fixed in 2.0.0-rc6.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/io.kestra:kestrato a version that resolves this vulnerability.Fixed in 2.0.0 - Upgrade
Upgrade
kestra-io/kestrato a version that resolves this vulnerability.Fixed in 2.0.0-rc6 - Configuration
Update Kestra configuration so Micronaut management endpoints served on port 8081 are bound to loopback only (not publicly reachable), preventing unauthenticated access to endpoints like GET /env and POST /loggers/{name}.
Kestra Micronaut management endpoints (port 8081) management port binding = bind port 8081 to loopback only - Configuration
Apply authentication to the Micronaut management endpoints on port 8081 by binding them behind the same auth as the API (or requiring a separate management credential), so the auth filter no longer applies only to /api/v1/** on port 8080.
Kestra Micronaut management endpoints (port 8081) management endpoint authentication = require authentication (same auth as API or separate management credential) - Configuration
Ensure the reference docker-compose.yml does not publish port 8081 to the host/network; keep port 8081 internal so untrusted clients cannot reach it.
reference docker-compose.yml / documentation publish management port 8081 = do not publish 8081 in reference compose - Configuration
Prominently document in SECURITY.md, application.yml, and the reference docker-compose that port 8081 must never be exposed to untrusted networks, because management endpoints on 8081 bypass API basic-auth.
SECURITY.md / application.yml security documentation for port 8081 exposure = prominently document that port 8081 must never be exposed to untrusted networks
Event History
Frequently Asked Questions
What is the risk level of CVE-2026-73245?
The risk level of CVE-2026-73245 is categorized as medium with a CVSS score of 6.5.
What endpoints are exposed in CVE-2026-73245?
CVE-2026-73245 exposes the /env and /loggers management endpoints on port 8081.
How do I fix CVE-2026-73245?
To fix CVE-2026-73245, upgrade Kestra to version 2.0.0-rc6 or later.
What vulnerabilities exist with CVE-2026-73245?
CVE-2026-73245 allows unauthenticated access to sensitive management information due to bypassing API basic-auth.
Is there a workaround for CVE-2026-73245?
As a workaround for CVE-2026-73245, you can restrict access to port 8081 via firewall rules until the software is updated.