DIRAS TAKE
Urgent — CISA added this vulnerability to the Known Exploited Vulnerabilities catalog with a near-term remediation deadline, which indicates authorities require immediate action; treat internet-exposed Kestra services as high priority to mitigate now.
What is CVE-2026-49869?
Unauthenticated attackers can create and run workflows on Kestra OSS, leading to remote code execution in worker containers. CVE-2026-49869 affects Kestra OSS releases matching the listed version ranges: versions less than 1.0.45, and versions >= 1.1.0 and < 1.3.21. The flaw is a suffix-based path check that allows bypassing Basic Auth for endpoints whose last segment is configs; no credentials are required and the product listens on network interfaces, so an attacker with network access can exploit it remotely. The weakness is classified as CWE-78 (OS Command Injection).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of Kestra Kestra OSS are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| kestra | < 1.0.45 | |
| kestra | >= 1.1.0, < 1.3.21 |
Is CVE-2026-49869 being exploited?
CISA added CVE-2026-49869 to the Known Exploited Vulnerabilities catalog on 2026-09-02, and US federal agencies must remediate by 2026-09-05. Public exploit code is available.
How to fix CVE-2026-49869
- Immediately restrict network exposure of Kestra OSS instances; block external access to the service and limit access to trusted hosts.
- Follow vendor instructions and implement any CISA-recommended mitigations; if running in cloud, follow BOD 26-04 guidance for patching or discontinue use until mitigations are in place.
- Disable or remove default script execution plugins (for example plugin-script-shell, plugin-script-python) where possible to reduce risk of command execution.
- Monitor Kestra and container logs for unexpected workflow creation or execution and isolate affected hosts if suspicious activity is found.
Frequently asked questions
Is CVE-2026-49869 being actively exploited?
CISA added CVE-2026-49869 to its Known Exploited Vulnerabilities catalog on 2026-09-02, and public exploit code is available.
Which Kestra OSS versions are affected by CVE-2026-49869?
Kestra OSS releases matching the reported affected ranges are impacted: versions older than 1.0.45, and versions greater than or equal to 1.1.0 but less than 1.3.21.
Is there a patch for CVE-2026-49869?
A vendor-supplied fixed version is not listed in the provided facts; follow vendor guidance and apply recommended mitigations or restrict service exposure until a vendor patch is available.
What can an attacker do with CVE-2026-49869?
An unauthenticated attacker can create and execute workflows on Kestra OSS; because script execution plugins are enabled by default, this can lead to remote code execution inside Kestra worker containers.
References
- nvd.nist.gov/vuln/detail/CVE-2026-49869
- cve.org/CVERecord?id=CVE-2026-49869
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-49869
- github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx
- All Kestra CVEs on CVE Radar
- CVEs published in September 2026