{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/kestra-oss--1.0.45/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kestra:kestra:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-49869"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Kestra OSS (\u003c 1.0.45)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","command-injection"],"_cs_type":"advisory","_cs_vendors":["Kestra"],"content_html":"\u003cp\u003eKestra OSS is affected by an OS command injection vulnerability (CVE-2026-49869) that enables unauthenticated remote attackers to interact with the platform's workflow execution engine. By exploiting this flaw, an attacker can bypass authentication mechanisms to create, inject, and execute arbitrary workflows. This represents a significant security risk, as the platform is designed to orchestrate system processes and automation tasks, granting a successful attacker the ability to perform operations with the privileges of the Kestra service. Defenders should prioritize auditing internet-facing Kestra instances, as this vulnerability provides a direct vector for remote code execution and potential lateral movement within a target environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-49869 allows an unauthenticated actor to execute arbitrary commands, potentially leading to unauthorized data exfiltration, system-wide disruption, or the establishment of persistent backdoors within the affected organization's infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately identify all internet-facing instances of Kestra OSS and verify their version against vendor-provided security patches.\u003c/li\u003e\n\u003cli\u003eReview all system-level logs for unauthorized workflow creation or execution requests originating from untrusted IP addresses.\u003c/li\u003e\n\u003cli\u003eImplement network-level restrictions to prevent public access to Kestra management interfaces unless strictly necessary for business operations.\u003c/li\u003e\n\u003cli\u003eAdhere to CISA BOD 26-04 requirements by ensuring the vulnerability is patched within the mandated timeframe (by 2026-09-05) and performing the required forensics triage as outlined in CISA's implementation guidance.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T17:56:15Z","date_published":"2026-09-02T17:56:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-kestra-rce/","summary":"Kestra OSS contains an OS command injection vulnerability allowing unauthenticated remote attackers to create and execute arbitrary workflows, posing a risk of full system compromise.","title":"Unauthenticated OS Command Injection in Kestra OSS (CVE-2026-49869)","url":"https://feed.craftedsignal.io/briefs/2026-09-kestra-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Kestra OSS (\u003c 1.0.45)","version":"https://jsonfeed.org/version/1.1"}