First published · Last updated
CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability
A reported OS command injection in Kestra OSS could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. The advisory instructs stakeholders to apply vendor mitigations and follow CISA BOD 26-04 and forensics triage guidance.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 6/10
- Geographic reach
- 4/10
- Global importance
- 4/10
- Impact magnitude
- 5/10
- Positivity
- 2/10
- Urgency
- 7/10
Why it matters
Exploitable remote command injection can enable unauthorized control of affected systems, so affected stakeholders must implement mitigations per CISA guidance.

