Skip to content
Threat Feed
critical advisory

Unauthenticated OS Command Injection in Kestra OSS (CVE-2026-49869)

Kestra OSS contains an OS command injection vulnerability allowing unauthenticated remote attackers to create and execute arbitrary workflows, posing a risk of full system compromise.

CVE search metadata

CVE search record: CVE-2026-49869. Severity: critical. CVSS: 10.0. EPSS: 0.99%. KEV: no. Product: Kestra OSS (< 1.0.45). Brief: Unauthenticated OS Command Injection in Kestra OSS (CVE-2026-49869). Brief link: https://feed.craftedsignal.io/briefs/2026-09-kestra-rce/

Kestra OSS is affected by an OS command injection vulnerability (CVE-2026-49869) that enables unauthenticated remote attackers to interact with the platform's workflow execution engine. By exploiting this flaw, an attacker can bypass authentication mechanisms to create, inject, and execute arbitrary workflows. This represents a significant security risk, as the platform is designed to orchestrate system processes and automation tasks, granting a successful attacker the ability to perform operations with the privileges of the Kestra service. Defenders should prioritize auditing internet-facing Kestra instances, as this vulnerability provides a direct vector for remote code execution and potential lateral movement within a target environment.

Impact

Successful exploitation of CVE-2026-49869 allows an unauthenticated actor to execute arbitrary commands, potentially leading to unauthorized data exfiltration, system-wide disruption, or the establishment of persistent backdoors within the affected organization's infrastructure.

Recommendation

  • Immediately identify all internet-facing instances of Kestra OSS and verify their version against vendor-provided security patches.
  • Review all system-level logs for unauthorized workflow creation or execution requests originating from untrusted IP addresses.
  • Implement network-level restrictions to prevent public access to Kestra management interfaces unless strictly necessary for business operations.
  • Adhere to CISA BOD 26-04 requirements by ensuring the vulnerability is patched within the mandated timeframe (by 2026-09-05) and performing the required forensics triage as outlined in CISA's implementation guidance.

Immediate actions

Patch Kestra OSS to 1.0.45 or later

IT Operations 2026-09-05

Mitigations

Patch Kestra OSS to 1.0.45 or later

immediate IT Operations

CVE-2026-49869