CVE-2026-49869 is an authentication bypass vulnerability in Kestra OSS that allows unauthenticated remote code execution. The defect exploits AuthenticationFilter treating any path ending in /configs as public, enabling attackers to create and execute workflows with shell tasks in the worker container. Users should upgrade to version 1.0.45 or 1.3.21 and restrict API access until patched.