Kestra Kestra OSS: Kestra OSS OS Command Injection Vulnerability

  • Thursday, 3rd September, 2026
  • 04:01am

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-49869

« Back