CPE
high
advisory
Unauthenticated SSRF in Kestra OSS via Pebble http() Function
1 rule 3 TTPs 1 CVE 1 IOCAn unauthenticated SSRF vulnerability in the Kestra OSS Pebble template engine allows remote attackers to perform arbitrary requests to internal network services and cloud metadata endpoints.
Kestra OSS
ssrf
vulnerability
kestra
1r
3t
1c
1i
critical
advisory
Unauthenticated OS Command Injection in Kestra OSS (CVE-2026-49869)
2 TTPs 1 CVEKestra OSS contains an OS command injection vulnerability allowing unauthenticated remote attackers to create and execute arbitrary workflows, posing a risk of full system compromise.
Kestra OSS
vulnerability
rce
command-injection
2t
1c
critical
advisory
Authentication Bypass and RCE in Kestra OSS
1 rule 3 TTPs 1 CVE 1 IOCKestra OSS versions 1.3.20 and below are vulnerable to an authentication bypass via an incorrectly implemented filter, enabling unauthenticated remote code execution with root privileges.
Kestra OSS
cve-2026-53576
rce
authentication-bypass
kestra
1r
3t
1c
1i