๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-49869: Kestra OSS OS Command Injection Vulnerability
infovulnerability๐ฅ Actively Exploited
security
Summary
Kestra OSS has a critical vulnerability that allows attackers without login credentials to create and run arbitrary workflows (automated task sequences) through OS command injection (inserting malicious commands into system inputs). The vulnerability is currently being exploited in real attacks.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 1.0%
Patch Available
Yes
Exploit Maturity
๐ฅ Actively Exploited
Disclosure Date
September 1, 2026
Classification
Attack SophisticationModerate
Affected Vendors
Monthly digest โ independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-49869
First tracked: September 2, 2026 at 02:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%