<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Kestra OSS (&lt; 1.0.45) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/kestra-oss--1.0.45/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 02 Sep 2026 17:56:15 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/kestra-oss--1.0.45/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated OS Command Injection in Kestra OSS (CVE-2026-49869)</title><link>https://feed.craftedsignal.io/briefs/2026-09-kestra-rce/</link><pubDate>Wed, 02 Sep 2026 17:56:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-kestra-rce/</guid><description>Kestra OSS contains an OS command injection vulnerability allowing unauthenticated remote attackers to create and execute arbitrary workflows, posing a risk of full system compromise.</description><content:encoded><![CDATA[<p>Kestra OSS is affected by an OS command injection vulnerability (CVE-2026-49869) that enables unauthenticated remote attackers to interact with the platform's workflow execution engine. By exploiting this flaw, an attacker can bypass authentication mechanisms to create, inject, and execute arbitrary workflows. This represents a significant security risk, as the platform is designed to orchestrate system processes and automation tasks, granting a successful attacker the ability to perform operations with the privileges of the Kestra service. Defenders should prioritize auditing internet-facing Kestra instances, as this vulnerability provides a direct vector for remote code execution and potential lateral movement within a target environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-49869 allows an unauthenticated actor to execute arbitrary commands, potentially leading to unauthorized data exfiltration, system-wide disruption, or the establishment of persistent backdoors within the affected organization's infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately identify all internet-facing instances of Kestra OSS and verify their version against vendor-provided security patches.</li>
<li>Review all system-level logs for unauthorized workflow creation or execution requests originating from untrusted IP addresses.</li>
<li>Implement network-level restrictions to prevent public access to Kestra management interfaces unless strictly necessary for business operations.</li>
<li>Adhere to CISA BOD 26-04 requirements by ensuring the vulnerability is patched within the mandated timeframe (by 2026-09-05) and performing the required forensics triage as outlined in CISA's implementation guidance.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>command-injection</category></item></channel></rss>