HIGHVulnerability
Verified
Global

CISA KEV: Kestra Kestra OSS — Kestra OSS OS Command Injection Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Analysis

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-02. Remediation due: 2026-09-05.

Indicators of Compromise (1)

CVE (1)
CVE-2026-49869
Source Attribution

Originally published by CISA KEV on Sep 2, 2026. Verified by: CISA.

Related Threats