CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability
Summary
Kestra OSS has an OS command injection vulnerability allowing unauthenticated remote attackers to execute arbitrary workflows. Users must apply vendor-provided mitigations or discontinue use if unavailable, adhering to CISA's guidance on prioritizing security updates.
IFF Assessment
The vulnerability allows unauthenticated remote attackers to execute arbitrary code, posing a significant risk to systems.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 05, 2026. Known ransomware use: Unknown.
Defender Context
This OS command injection vulnerability in Kestra OSS is a critical finding. Defenders should prioritize patching or mitigating this vulnerability, especially considering the potential for unauthenticated remote code execution. The lack of authentication required for exploitation makes it a prime target for automated attacks.