type: vulnerability ยท created: 2026-09-03 ยท updated: 2026-09-03 ยท tags: ["cve", "vulnerability", "command-injection", "kestra"] ยท confidence: high ยท severity: high ยท affected_sectors: ["Technology", "Government"] ยท au_impact: true
CVE-2026-49869
Affected product: Kestra OSS (OS command injection)
Patched version: Refer to vendor advisory
Active exploitation: Yes โ added to CISA KEV catalog on 2026-09-02
Assessment
CISA added this OS command injection in Kestra OSS to its Known Exploited Vulnerabilities catalog, confirming active exploitation. Kestra is a workflow orchestration platform, and command injection in it can let an attacker execute arbitrary operating-system commands on the orchestrator host. Organisations running Kestra should prioritise patching and review exposure of the platform to untrusted input.