


Perceptive Security
SOC/SIEM Consultancy

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without …
Published:
2 september 2026 om 02:00:00
Alert date:
2 september 2026 om 20:06:16
Source:
cisa.gov

Web Technologies, Supply Chain & Dependencies, Zero-Day Vulnerabilities, Enterprise Applications
Kestra OSS contains a critical OS command injection vulnerability tracked as CVE-2026-49869. The flaw allows unauthenticated remote attackers to create and execute arbitrary workflows without any credentials. This represents a significant security risk as it requires no authentication to exploit. The vulnerability affects an open-source component that may be used by multiple products. CISA has flagged this under BOD 26-04, which prioritizes security updates based on risk. The advisory references the GitHub Security Advisory GHSA-5vc5-wxxq-3fjx for additional technical details. Organizations using Kestra OSS are urged to apply security updates promptly. Forensic triage requirements are also outlined under BOD 26-04 implementation guidance.
Technical details
Mitigation steps:
Affected products:
Kestra OSS
Related links:
https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx
https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
https://nvd.nist.gov/vuln/detail/CVE-2026-49869
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.