Breaches  › Tech  › Kestra Kestra OSS
high · tech · Disclosed Sep 2, 2026

Kestra Kestra OSS

Kestra OSS OS Command Injection Vulnerability — Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Original Disclosure
https://nvd.nist.gov/vuln/detail/CVE-2026-49869
Read original
Severity
high
Sector
tech
Disclosure date
September 2, 2026
Indexed
17 hours, 35 minutes ago