THREATOPS
THREAT OPSCVEs › CVE-2026-49869

CVE-2026-49869 — Kestra OSS OS Command Injection Vulnerability

CISA KEVExploited: confirmedKestra

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Vulnerability details

Related reporting