Kestra Kestra OSS: Kestra OSS OS Command Injection Vulnerability

  • Saturday, 5th September, 2026
  • 16:01pm

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-49869

« Back