THREAT OPS › CVEs › CVE-2026-49869
CVE-2026-49869 — Kestra OSS OS Command Injection Vulnerability
Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
Vulnerability details
- Affected productsKestra OSS
- KEV remediation due2026-09-05
Related reporting
- [NVD] CVE-2026-49869 (CRITICAL 10.0) — Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather thanvd
- CISA Adds Seven Known Exploited Vulnerabilities to Catalogcisa_advisories
- [CISA KEV] CVE-2026-49869 — Kestra Kestra OSS: Kestra OSS OS Command Injection Vulnerabilitycisa_kev
- When AI infrastructure becomes the target: Securing gateways and control pointsmsstic
- When AI infrastructure becomes the target: Securing gateways and control pointsmsstic