Security
Loading…

CVE-2026-49869

CRITICALCVSS 10.0Known Exploited
Description

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Timeline
Published:June 26th, 2026 10:16 PM
Last modified:September 3rd, 2026 1:05 PM
Added to KEV:September 2nd, 2026
CVSS Scoring

CVSS v3: 10.0 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

kestra

Products

kestra

Source: NIST NVD · Data may lag official sources by up to one minute