Home ยท Wiki ยท Vulnerabilities & CVEs
type: vulnerability ยท created: 2026-09-03 ยท updated: 2026-09-03 ยท tags: ["cve", "vulnerability", "command-injection", "kestra"] ยท confidence: high ยท severity: high ยท affected_sectors: ["Technology", "Government"] ยท au_impact: true

CVE-2026-49869

Affected product: Kestra OSS (OS command injection)

Patched version: Refer to vendor advisory

Active exploitation: Yes โ€” added to CISA KEV catalog on 2026-09-02

Assessment

CISA added this OS command injection in Kestra OSS to its Known Exploited Vulnerabilities catalog, confirming active exploitation. Kestra is a workflow orchestration platform, and command injection in it can let an attacker execute arbitrary operating-system commands on the orchestrator host. Organisations running Kestra should prioritise patching and review exposure of the platform to untrusted input.