RaqibCTI
CVE

CVE-2026-49869

P2
Kestra OSS OS Command Injection Vulnerability
Kestra · Kestra OSS
Date added (CISA)
2026-09-02
Remediation due
2026-09-05
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date
Associated with
Related to
  • payload · AmateracampaignCorrelated cluster2026-09-21
  • payload · XMRigcampaignCorrelated cluster2026-09-03
  • payload · XMRigcampaignCorrelated cluster2026-08-26

Description

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Source: NVD ↗ · CISA KEV Catalog ↗

CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability · RaqibCTI