CVE-2026-49869CISA KEVEPSS p81.0%

CVE-2026-49869Kestra OSS OS Command Injection Vulnerability

Kestra / Kestra OSS

Description

Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

Scoring

CVSS 10.0 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS2.10% probability of exploitation · percentile 81.0% · 2026-10-05T12:00:23Z
Last modified2026-09-03

CISA KEV entry

Added to KEV: 2026-09-02

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.