• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-49869: pre-auth remote code execution in Kestra Kestra OSS

Unauthenticated attackers can create and run workflows on Kestra OSS, leading to remote code execution in worker containers. CVE-2026-49869 affects Kestra OSS releases matching the listed version ranges: versions less than 1.0.45, and versions >= 1.1.0 and < 1.3.21. The flaw is a suffix-based path check that allows bypassing Basic Auth for endpoints whose last segment is configs; no credentials are required and the product listens on network interfaces, so an attacker with network access can exploit it remotely.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
10CRITICAL
EPSS
0.02095
CWE
CWE-78
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent — CISA added this vulnerability to the Known Exploited Vulnerabilities catalog with a near-term remediation deadline, which indicates authorities require immediate action; treat internet-exposed Kestra services as high priority to mitigate now.

What is CVE-2026-49869?

Unauthenticated attackers can create and run workflows on Kestra OSS, leading to remote code execution in worker containers. CVE-2026-49869 affects Kestra OSS releases matching the listed version ranges: versions less than 1.0.45, and versions >= 1.1.0 and < 1.3.21. The flaw is a suffix-based path check that allows bypassing Basic Auth for endpoints whose last segment is configs; no credentials are required and the product listens on network interfaces, so an attacker with network access can exploit it remotely. The weakness is classified as CWE-78 (OS Command Injection).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Kestra Kestra OSS are affected?

BRANCHAFFECTEDFIXED
kestra< 1.0.45
kestra>= 1.1.0, < 1.3.21

Is CVE-2026-49869 being exploited?

CISA added CVE-2026-49869 to the Known Exploited Vulnerabilities catalog on 2026-09-02, and US federal agencies must remediate by 2026-09-05. Public exploit code is available.

How to fix CVE-2026-49869

  1. Immediately restrict network exposure of Kestra OSS instances; block external access to the service and limit access to trusted hosts.
  2. Follow vendor instructions and implement any CISA-recommended mitigations; if running in cloud, follow BOD 26-04 guidance for patching or discontinue use until mitigations are in place.
  3. Disable or remove default script execution plugins (for example plugin-script-shell, plugin-script-python) where possible to reduce risk of command execution.
  4. Monitor Kestra and container logs for unexpected workflow creation or execution and isolate affected hosts if suspicious activity is found.

Frequently asked questions

Is CVE-2026-49869 being actively exploited?

CISA added CVE-2026-49869 to its Known Exploited Vulnerabilities catalog on 2026-09-02, and public exploit code is available.

Which Kestra OSS versions are affected by CVE-2026-49869?

Kestra OSS releases matching the reported affected ranges are impacted: versions older than 1.0.45, and versions greater than or equal to 1.1.0 but less than 1.3.21.

Is there a patch for CVE-2026-49869?

A vendor-supplied fixed version is not listed in the provided facts; follow vendor guidance and apply recommended mitigations or restrict service exposure until a vendor patch is available.

What can an attacker do with CVE-2026-49869?

An unauthenticated attacker can create and execute workflows on Kestra OSS; because script execution plugins are enabled by default, this can lead to remote code execution inside Kestra worker containers.

References