CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability

Summary

Kestra OSS has an OS command injection vulnerability allowing unauthenticated remote attackers to execute arbitrary workflows. Users must apply vendor-provided mitigations or discontinue use if unavailable, adhering to CISA's guidance on prioritizing security updates.

IFF Assessment

FOE

The vulnerability allows unauthenticated remote attackers to execute arbitrary code, posing a significant risk to systems.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 05, 2026. Known ransomware use: Unknown.

Defender Context

This OS command injection vulnerability in Kestra OSS is a critical finding. Defenders should prioritize patching or mitigating this vulnerability, especially considering the potential for unauthenticated remote code execution. The lack of authentication required for exploitation makes it a prime target for automated attacks.

Read Full Story →