top of page
perceptive_background_267k.jpg

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without …

Published:

2 september 2026 om 02:00:00

Alert date:

2 september 2026 om 20:06:16

Source:

cisa.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies, Zero-Day Vulnerabilities, Enterprise Applications

Kestra OSS contains a critical OS command injection vulnerability tracked as CVE-2026-49869. The flaw allows unauthenticated remote attackers to create and execute arbitrary workflows without any credentials. This represents a significant security risk as it requires no authentication to exploit. The vulnerability affects an open-source component that may be used by multiple products. CISA has flagged this under BOD 26-04, which prioritizes security updates based on risk. The advisory references the GitHub Security Advisory GHSA-5vc5-wxxq-3fjx for additional technical details. Organizations using Kestra OSS are urged to apply security updates promptly. Forensic triage requirements are also outlined under BOD 26-04 implementation guidance.

Technical details

Mitigation steps:

Affected products:

Kestra OSS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page